Skip to content
VaultGHSA-qv3p-fmv3-9hww

Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse

Medium6.5CVE-2025-6014 · Published Aug 1, 2025 · updated Sep 10, 2026

Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.20.11.20.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-156
Also known as
BIT-vault-2025-6014, CVE-2025-6014, GO-2025-3841

More Vault advisories

All Vault
Advisory
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Medium6.8Aug 1, 2025
Hashicorp Vault has Privilege Escalation Vulnerability
High7.2Aug 1, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
Critical9.1Aug 1, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Low3.7Aug 1, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Medium5.3Aug 1, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Medium5.7Aug 1, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.