CVE-2025-4656

Source
https://cve.org/CVERecord?id=CVE-2025-4656
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4656.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-4656
Aliases
Downstream
Related
Published
2025-06-25T17:15:38.440Z
Modified
2026-03-23T05:08:17.500375253Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.

References

Affected packages

Git / github.com/hashicorp/vault

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/vault
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.14.8"
        },
        {
            "fixed": "1.20.0"
        }
    ]
}

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "1.14.8"
            },
            {
                "fixed": "1.16.22"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "1.17.0"
            },
            {
                "fixed": "1.17.17"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "1.18.0"
            },
            {
                "fixed": "1.18.11"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "1.19.0"
            },
            {
                "fixed": "1.19.6"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4656.json"