Hashicorp Vault vulnerable to denial of service through memory exhaustion
High7.5CVE-2024-8185 · Published Oct 31, 2024 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/openbao/openbao Go | < 2.0.3 | 2.0.3 |
| github.com/hashicorp/vault Go | >= 1.2.0, < 1.18.1 | 1.18.1 |
Details and references
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint. An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself. This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-636
- Also known as
- BIT-openbao-2024-8185, BIT-vault-2024-8185, CVE-2024-8185, GO-2024-3246
- nvd.nist.gov/vuln/detail/CVE-2024-8185
- github.com/hashicorp/vault/commit/195dfca433028887973f5bd82d173d91fe9dab4a
- discuss.hashicorp.com/t/hcsec-2024-26-vault-vulnerable-to-denial-of-service-through-memory-exhaustion-when-processing-raft-cluster-join-requests/71047
- github.com/hashicorp/vault
- openbao.org/docs/release-notes/2-0-0/#203
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 102024 | Vault Community Edition privilege escalation vulnerability CVE-2024-9180High7.2fixed in 1.18.0 | High7.2 | 1.18.0 |
| Sep 22024 | Vault Leaks Client Token and Token Accessor in Audit Devices CVE-2024-8365Medium6.5fixed in 1.17.5 | Medium6.5 | 1.17.5 |
| Jul 112024 | Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions CVE-2024-6468High7.5fixed in 1.15.12, 1.16.3, 1.17.2 | High7.5 | 1.15.12, 1.16.3, 1.17.2 |
| Jun 122024 | HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims CVE-2024-5798Low2.6fixed in 1.15.9, 1.16.3, 1.17.0 | Low2.6 | 1.15.9, 1.16.3, 1.17.0 |
| May 22025 | Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information CVE-2025-4166Medium4.5fixed in 1.19.3 | Medium4.5 | 1.19.3 |
| May 22025 | Hashicorp Vault Community vulnerable to Incorrect Authorization CVE-2025-3879Medium6.6fixed in 1.19.1 | Medium6.6 | 1.19.1 |