CVE-2026-4525Sensitive Info Insertion into Sent Data in Vault

Severity
7.5HIGHNVD
EPSS
0.0%
top 97.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17

Description

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages11 packages

CVEListV5hashicorp/vault0.11.22.0.0
CVEListV5hashicorp/vault_enterprise0.11.22.0.0
Gogithub.com/hashicorp_vault0.11.21.21.4

🔴Vulnerability Details

1
GHSA
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization2026-04-17

📋Vendor Advisories

1
Red Hat
Vault: Vault: Information disclosure of authentication tokens via incorrect header handling2026-04-17

💬Community

1
Bugzilla
CVE-2026-4525 Vault: Vault: Information disclosure of authentication tokens via incorrect header handling2026-04-17