HIGH7.5
GHSA-72gw-fmmr-c4r4
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
Details
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0.11.2No fixed version published yet for github.com/hashicorp/vault (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-4525[ADVISORY]
- https://access.redhat.com/security/cve/CVE-2026-4525[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2459107[WEB]
- https://discuss.hashicorp.com/t/hcsec-2026-07-vault-may-expose-tokens-to-auth-plugins-due-to-incorrect-header-sanitization/77344[WEB]
- https://github.com/advisories/GHSA-72gw-fmmr-c4r4[ADVISORY]
- https://github.com/hashicorp/vault[PACKAGE]
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4525.json[WEB]