VaultGHSA-qv3p-fmv3-9hww
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
Medium6.5CVE-2025-6014 · Published Aug 1, 2025 · updated Sep 10, 2026
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | < 1.20.1 | 1.20.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-156
- Also known as
- BIT-vault-2025-6014, CVE-2025-6014, GO-2025-3841
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12025 | Hashicorp Vault has Incorrect Validation for Non-CA Certificates | Medium6.8 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Privilege Escalation Vulnerability | High7.2 | 1.20.0 |
| Aug 12025 | Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration | Critical9.1 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users | Low3.7 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Lockout Feature Authentication Bypass | Medium5.3 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability | Medium5.7 | 1.20.1 |