BIT-openbao-2025-59043

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/openbao/BIT-openbao-2025-59043.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-openbao-2025-59043
Aliases
Published
2026-07-27T05:48:59Z
Modified
2026-09-08T08:45:15Z
Summary
OpenBao vulnerable to denial of service via malicious JSON request processing
Details

OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their serialized version. It is possible to craft a JSON payload to maximize the factor between serialized memory usage and deserialized memory usage, similar to a zip bomb, with factors reaching approximately 35. This can be used to circumvent the max_request_size configuration parameter which is intended to protect against denial of service attacks. The request body is parsed into a map very early in the request handling chain before authentication, which means an unauthenticated attacker can send a specifically crafted JSON object and cause an out-of-memory crash. Additionally, for requests with large numbers of strings, the audit subsystem can consume large quantities of CPU. The vulnerability is fixed in version 2.4.1.

Database specific
{
    "cpes": [
        "cpe:2.3:a:openbao:openbao:*:*:*:*:*:go:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / openbao

Package

Name
openbao
Purl
pkg:bitnami/openbao

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/openbao/BIT-openbao-2025-59043.json"