Skip to content
VaultGHSA-gcqf-f89c-68hv

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

Medium4.5CVE-2025-4166 · Published May 2, 2025 · updated Sep 10, 2026

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 0.3.0, < 1.19.31.19.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-209
Also known as
BIT-openbao-2025-4166, BIT-vault-2025-4166, CVE-2025-4166, GO-2025-3663

More Vault advisories

All Vault
Advisory
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Medium5.7Aug 1, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
Medium6.5Aug 1, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Medium5.3Aug 1, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Low3.7Aug 1, 2025
Vault Community Edition rekey and recovery key operations can cause denial of service
Low3.1Jun 26, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization
Medium6.6May 2, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.