Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
[
{
"events": [
{
"introduced": "1.14.8"
},
{
"fixed": "1.16.22"
}
]
},
{
"events": [
{
"introduced": "1.17.0"
},
{
"fixed": "1.17.17"
}
]
},
{
"events": [
{
"introduced": "1.18.0"
},
{
"fixed": "1.18.11"
}
]
},
{
"events": [
{
"introduced": "1.19.0"
},
{
"fixed": "1.19.6"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4656.json"