Skip to content
VaultGHSA-v6r4-35f9-9rpw

Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability

Medium5.7CVE-2025-6015 · Published Aug 1, 2025 · updated Sep 10, 2026

Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.10.0, < 1.20.11.20.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-307
Also known as
BIT-vault-2025-6015, CVE-2025-6015, GO-2025-3842

More Vault advisories

All Vault
Advisory
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Medium6.8Aug 1, 2025
Hashicorp Vault has Privilege Escalation Vulnerability
High7.2Aug 1, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
Critical9.1Aug 1, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Low3.7Aug 1, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Medium5.3Aug 1, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
Medium6.5Aug 1, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.