VaultGHSA-72gw-fmmr-c4r4
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
High7.5CVE-2026-4525 · Published Apr 17, 2026 · updated Sep 10, 2026
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 0.11.2, <= 1.21.4 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-201
- Also known as
- BIT-vault-2026-4525, CVE-2026-4525, GO-2026-5199
- nvd.nist.gov/vuln/detail/CVE-2026-4525
- access.redhat.com/security/cve/CVE-2026-4525
- bugzilla.redhat.com/show_bug.cgi?id=2459107
- discuss.hashicorp.com/t/hcsec-2026-07-vault-may-expose-tokens-to-auth-plugins-due-to-incorrect-header-sanitization/77344
- github.com/advisories/GHSA-72gw-fmmr-c4r4
- github.com/hashicorp/vault
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4525.json
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 17 | HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations | High7.5 | No fix yet |
| Apr 17 | HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS | Medium5.3 | No fix yet |
| Apr 17 | HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service | High8.1 | No fix yet |
| Oct 232025 | Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON | High7.5 | 1.21.0 |
| Oct 232025 | HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass | High8.1 | 1.21.0 |
| Aug 282025 | HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads | High7.5 | 1.20.3 |