openbaoGHSA-q8cj-789h-vg24
OpenBao's Inline Auth Incorrectly Redacted Headers
MediumCVE-2026-46358 · Published May 28, 2026 · updated Aug 17, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/openbao/openbao Go | < 2.5.4 | 2.5.4 |
Details and references
### Impact OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device. Operators should review leaked source authentication material and rotate it as appropriate. ### Patches This is fixed in OpenBao v2.5.4. ### Resources https://github.com/openbao/openbao/issues/3074
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- BIT-openbao-2026-46358, CVE-2026-46358, GO-2026-5574
More openbao advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 28 | OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL CVE-2026-45808Highfixed in 2.5.4 | High | 2.5.4 |
| May 28 | OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens CVE-2026-46405Medium5.3fixed in 2.5.4 | Medium5.3 | 2.5.4 |
| May 5 | OpenBao's Namespace Deletion May Not Delete Data Properly CVE-2026-42186Lowfixed in 0.0.0-20260420173541-6d2e0506e2b4 | Low | 0.0.0-20260420173541-6d2e0506e2b4 |
| Jun 19 | OpenBao: LDAPi ldaputil (wrong escape func) CVE-2026-55770Medium6.8fixed in 0.0.0-20260617104213-10b7825c714c | Medium6.8 | 0.0.0-20260617104213-10b7825c714c |
| Jun 19 | OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} , incomplete fix of CVE-2026-45808 CVE-2026-55774Lowfixed in 0.0.0-20260617103932-b20b999dd404 | Low | 0.0.0-20260617103932-b20b999dd404 |
| Jun 19 | OpenBao's System Backend allows Unauthorized Management of the containing Namespace CVE-2026-55775Lowfixed in 0.0.0-20260617103935-d3c1cc64b1ae | Low | 0.0.0-20260617103935-d3c1cc64b1ae |