GHSA-34fc-gh42-pj53

Suggest an improvement
Source
https://github.com/advisories/GHSA-34fc-gh42-pj53
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-34fc-gh42-pj53/GHSA-34fc-gh42-pj53.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-34fc-gh42-pj53
Aliases
Published
2026-09-22T20:36:51Z
Modified
2026-09-22T21:00:03Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
Details

Impact

When running in the highly privileged recovery mode, OpenBao was vulnerable to a timing attack against the single recovery token. This allowed an attacker to extract the recovery token and use it to perform operations against the OpenBao instance, including reading or modification of data.

Patches

This has been patched in OpenBao v2.6.0.

Database specific
{
    "cwe_ids":  [
        "CWE-208"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-22T20:36:51Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

Go / github.com/openbao/openbao

Package

Name
github.com/openbao/openbao
View open source insights on deps.dev
Purl
pkg:golang/github.com/openbao/openbao

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20260713141742-763625a20721

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-34fc-gh42-pj53/GHSA-34fc-gh42-pj53.json"

Go / github.com/openbao/openbao

Package

Name
github.com/openbao/openbao
View open source insights on deps.dev
Purl
pkg:golang/github.com/openbao/openbao

Affected ranges

Type
SEMVER
Events
Introduced
0.1.0
Last Affected
1.1.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-34fc-gh42-pj53/GHSA-34fc-gh42-pj53.json"