Skip to content
VaultGHSA-mwgr-84fv-3jh9

Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users

Low3.7CVE-2025-6011 · Published Aug 1, 2025 · updated Sep 10, 2026

A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.20.11.20.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-203
Also known as
BIT-vault-2025-6011, CVE-2025-6011, GO-2025-3839

More Vault advisories

All Vault
Advisory
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Medium6.8Aug 1, 2025
Hashicorp Vault has Privilege Escalation Vulnerability
High7.2Aug 1, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
Critical9.1Aug 1, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Medium5.3Aug 1, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
Medium6.5Aug 1, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Medium5.7Aug 1, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.