HIGH8.1
GHSA-9g4h-h484-3578
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass
Quick fix
GHSA-9g4h-h484-3578 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.21.0Details
Vault and Vault Enterprise's ("Vault") AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0.6.0Fixed in: 1.21.0Fix
go get github.com/hashicorp/vault@v1.21.0References
- https://nvd.nist.gov/vuln/detail/CVE-2025-11621[ADVISORY]
- https://github.com/hashicorp/vault/commit/8d07273d14ae7f5a48cc96f66cc86615dea83390[WEB]
- https://discuss.hashicorp.com/t/hcsec-2025-30-vault-aws-auth-method-authentication-bypass-through-mishandling-of-cache-entries/76709[WEB]
- https://github.com/hashicorp/vault[PACKAGE]