VaultGHSA-v6r4-35f9-9rpw
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Medium5.7CVE-2025-6015 · Published Aug 1, 2025 · updated Sep 10, 2026
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.10.0, < 1.20.1 | 1.20.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-307
- Also known as
- BIT-vault-2025-6015, CVE-2025-6015, GO-2025-3842
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12025 | Hashicorp Vault has Incorrect Validation for Non-CA Certificates | Medium6.8 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Privilege Escalation Vulnerability | High7.2 | 1.20.0 |
| Aug 12025 | Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration | Critical9.1 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users | Low3.7 | 1.20.1 |
| Aug 12025 | Hashicorp Vault has Lockout Feature Authentication Bypass | Medium5.3 | 1.20.1 |
| Aug 12025 | Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse | Medium6.5 | 1.20.1 |