BIT-vault-2026-4525

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/vault/BIT-vault-2026-4525.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-vault-2026-4525
Aliases
Published
2026-04-21T12:15:54Z
Modified
2026-09-10T16:01:48Z
Summary
Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
Details

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Database specific
{
    "cpes": [
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:go:*:*",
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:go:*:*",
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:community:go:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / vault

Package

Name
vault
Purl
pkg:bitnami/vault

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0.10.0
Fixed
2.0.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/vault/BIT-vault-2026-4525.json"