Skip to content
openbaoGHSA-q8cj-789h-vg24

OpenBao's Inline Auth Incorrectly Redacted Headers

MediumCVE-2026-46358 · Published May 28, 2026 · updated Aug 17, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 2.5.42.5.4
Details and references

### Impact OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device. Operators should review leaked source authentication material and rotate it as appropriate. ### Patches This is fixed in OpenBao v2.5.4. ### Resources https://github.com/openbao/openbao/issues/3074

CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-532
Also known as
BIT-openbao-2026-46358, CVE-2026-46358, GO-2026-5574

More openbao advisories

All
DateAdvisory
May 28OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
CVE-2026-45808Highfixed in 2.5.4
May 28OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens
CVE-2026-46405Medium5.3fixed in 2.5.4
May 5OpenBao's Namespace Deletion May Not Delete Data Properly
CVE-2026-42186Lowfixed in 0.0.0-20260420173541-6d2e0506e2b4
Jun 19OpenBao: LDAPi ldaputil (wrong escape func)
CVE-2026-55770Medium6.8fixed in 0.0.0-20260617104213-10b7825c714c
Jun 19OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} , incomplete fix of CVE-2026-45808
CVE-2026-55774Lowfixed in 0.0.0-20260617103932-b20b999dd404
Jun 19OpenBao's System Backend allows Unauthorized Management of the containing Namespace
CVE-2026-55775Lowfixed in 0.0.0-20260617103935-d3c1cc64b1ae

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.