Skip to content
OpenBaoGHSA-vv66-6rp4-wr4f

OpenBao's Namespace Deletion May Not Delete Data Properly

LowCVE-2026-42186 · Published May 5, 2026 · updated Jul 27, 2026

### Impact When OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around. ### Patches This will be patched in OpenBao v2.5.3. ### Workarounds Users may manually remove mounts prior to deleting the namespace. Audit logs may be used to identify repeated deletion attempts against the same namespace; `sys/raw` can be used to see what leases were not correctly deleted.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 0.0.0-20260420173541-6d2e0506e2b40.0.0-20260420173541-6d2e0506e2b4
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-212
Also known as
BIT-openbao-2026-42186, CVE-2026-42186, GO-2026-5674

More OpenBao advisories

All OpenBao
Advisory
OpenBao's Inline Auth Incorrectly Redacted Headers
MediumMay 28
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
HighMay 28
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
LowApr 21
OpenBao's SQL Injection in PostgreSQL database secrets engine
Medium4.9Apr 21
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low3.1Apr 21
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low3.1Apr 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.