VaultGHSA-fhc2-8qx8-6vj7
Vault Community Edition rekey and recovery key operations can cause denial of service
Low3.1CVE-2025-4656 · Published Jun 26, 2025 · updated Sep 10, 2026
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.14.8, < 1.20.0 | 1.20.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1088
- Also known as
- BIT-vault-2025-4656, CVE-2025-4656, GO-2025-3788
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12025 | Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability | Medium5.7 | 1.20.1 |
| Aug 12025 | Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse | Medium6.5 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Lockout Feature Authentication Bypass | Medium5.3 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users | Low3.7 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration | Critical9.1 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Privilege Escalation Vulnerability | High7.2 | 1.20.0 |