Skip to content
VaultGHSA-hwc3-3qh6-r4gg

HashiCorp Vault's PKI mount vulnerable to denial of service

Medium6.5CVE-2023-0665 · Published Mar 30, 2023 · updated Sep 10, 2026

HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.11.91.11.9
>= 1.12.0, < 1.12.51.12.5
>= 1.13.0, < 1.13.11.13.1
Details and references

More Vault advisories

All Vault
Advisory
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration
Medium5.3Aug 1, 2023
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
High8.1Jul 6, 2023
HashiCorp Vault's revocation list not respected
Medium5.3Jul 6, 2023
Hashicorp Vault vulnerable to Cross-site Scripting
Medium4.3Jun 9, 2023
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File
Medium6.7Mar 30, 2023
HashiCorp Vault's implementation of Shamir's secret sharing vulnerable to cache-timing attacks
Medium4.7Mar 30, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.