Skip to content
vaultGHSA-g233-2p4r-3q7v

Hashicorp Vault vulnerable to denial of service through memory exhaustion

High7.5CVE-2024-8185 · Published Oct 31, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 2.0.32.0.3
github.com/hashicorp/vault
Go
>= 1.2.0, < 1.18.11.18.1
Details and references

Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint. An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself. This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-636
Also known as
BIT-openbao-2024-8185, BIT-vault-2024-8185, CVE-2024-8185, GO-2024-3246

More vault advisories

All
DateAdvisory
Oct 102024Vault Community Edition privilege escalation vulnerability
CVE-2024-9180High7.2fixed in 1.18.0
Sep 22024Vault Leaks Client Token and Token Accessor in Audit Devices
CVE-2024-8365Medium6.5fixed in 1.17.5
Jul 112024Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
CVE-2024-6468High7.5fixed in 1.15.12, 1.16.3, 1.17.2
Jun 122024HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
CVE-2024-5798Low2.6fixed in 1.15.9, 1.16.3, 1.17.0
May 22025Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2025-4166Medium4.5fixed in 1.19.3
May 22025Hashicorp Vault Community vulnerable to Incorrect Authorization
CVE-2025-3879Medium6.6fixed in 1.19.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.