VaultGHSA-gcqf-f89c-68hv
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Medium4.5CVE-2025-4166 · Published May 2, 2025 · updated Sep 10, 2026
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 0.3.0, < 1.19.3 | 1.19.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-209
- Also known as
- BIT-openbao-2025-4166, BIT-vault-2025-4166, CVE-2025-4166, GO-2025-3663
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12025 | Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability | Medium5.7 | 1.20.1 |
| Aug 12025 | Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse | Medium6.5 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Lockout Feature Authentication Bypass | Medium5.3 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users | Low3.7 | 1.20.1 |
| Jun 262025 | Vault Community Edition rekey and recovery key operations can cause denial of service | Low3.1 | 1.20.0 |
| May 22025 | Hashicorp Vault Community vulnerable to Incorrect Authorization | Medium6.6 | 1.19.1 |