vaultGHSA-4qhc-v8r6-8vwm
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
High7.5CVE-2023-5954 · Published Nov 9, 2023 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | < 1.13.10 | 1.13.10 |
| >= 1.14.0, < 1.14.6 | 1.14.6 | |
| >= 1.15.0, < 1.15.2 | 1.15.2 |
Details and references
HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-401
- Also known as
- BIT-vault-2023-5954, CVE-2023-5954, GO-2023-2329
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 92023 | Memory exhaustion in HashiCorp Vault CVE-2023-6337High7.5fixed in 1.13.12, 1.14.8, 1.15.4 | High7.5 | 1.13.12, 1.14.8, 1.15.4 |
| Sep 292023 | Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability CVE-2023-5077High7.6fixed in 1.13.0 | High7.6 | 1.13.0 |
| Sep 152023 | HashiCorp Vault Improper Input Validation vulnerability CVE-2023-4680Medium6.8fixed in 1.12.11, 1.13.7, 1.14.3 | Medium6.8 | 1.12.11, 1.13.7, 1.14.3 |
| Jan 302024 | HashiCorp Vault Improper Privilege Management CVE-2020-10661Critical9.1fixed in 1.3.4 | Critical9.1 | 1.3.4 |
| Jan 302024 | HashiCorp Vault Improper Privilege Management CVE-2020-10660Medium5.3fixed in 1.3.4 | Medium5.3 | 1.3.4 |
| Jan 312024 | HashiCorp Vault Authentication bypass CVE-2020-16251High8.2fixed in 1.2.5, 1.3.8, 1.4.4, 1.5.1 | High8.2 | 1.2.5, 1.3.8, 1.4.4, 1.5.1 |