Skip to content
vaultGHSA-8f82-53h8-2p34

HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads

High7.5CVE-2025-6203 · Published Aug 28, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.20.31.20.3
Details and references

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unresponsive. This vulnerability, CVE-2025-6203, is fixed in Vault Community Edition 1.20.3 and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-770
Also known as
BIT-vault-2025-6203, CVE-2025-6203, GO-2025-3924

More vault advisories

All
DateAdvisory
Aug 62025HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-6013Medium6.5fixed in 1.20.2
Aug 12025Hashicorp Vault has Incorrect Validation for Non-CA Certificates
CVE-2025-6037Medium6.8fixed in 1.20.1
Aug 12025Hashicorp Vault has Privilege Escalation Vulnerability
CVE-2025-5999High7.2fixed in 1.20.0
Aug 12025Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
CVE-2025-6000Critical9.1fixed in 1.20.1
Aug 12025Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
CVE-2025-6011Low3.7fixed in 1.20.1
Aug 12025Hashicorp Vault has Lockout Feature Authentication Bypass
CVE-2025-6004Medium5.3fixed in 1.20.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.