VaultGHSA-qgj7-fmq2-6cc4
Hashicorp Vault has Lockout Feature Authentication Bypass
Medium5.3CVE-2025-6004 · Published Aug 1, 2025 · updated Sep 10, 2026
Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.13.0, < 1.20.1 | 1.20.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-307
- Also known as
- BIT-vault-2025-6004, CVE-2025-6004, GO-2025-3840
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12025 | Hashicorp Vault has Incorrect Validation for Non-CA Certificates | Medium6.8 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Privilege Escalation Vulnerability | High7.2 | 1.20.0 |
| Aug 12025 | Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration | Critical9.1 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users | Low3.7 | 1.20.1 |
| Aug 12025 | Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse | Medium6.5 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability | Medium5.7 | 1.20.1 |