vaultGHSA-8f82-53h8-2p34
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads
High7.5CVE-2025-6203 · Published Aug 28, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | < 1.20.3 | 1.20.3 |
Details and references
A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unresponsive. This vulnerability, CVE-2025-6203, is fixed in Vault Community Edition 1.20.3 and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-770
- Also known as
- BIT-vault-2025-6203, CVE-2025-6203, GO-2025-3924
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 62025 | HashiCorp Vault ldap auth method may not have correctly enforced MFA CVE-2025-6013Medium6.5fixed in 1.20.2 | Medium6.5 | 1.20.2 |
| Aug 12025 | Hashicorp Vault has Incorrect Validation for Non-CA Certificates CVE-2025-6037Medium6.8fixed in 1.20.1 | Medium6.8 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Privilege Escalation Vulnerability CVE-2025-5999High7.2fixed in 1.20.0 | High7.2 | 1.20.0 |
| Aug 12025 | Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration CVE-2025-6000Critical9.1fixed in 1.20.1 | Critical9.1 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users CVE-2025-6011Low3.7fixed in 1.20.1 | Low3.7 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Lockout Feature Authentication Bypass CVE-2025-6004Medium5.3fixed in 1.20.1 | Medium5.3 | 1.20.1 |