Feed/CVE-2026-4525
CVE-2026-4525HIGHCVSS 7.5

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

Published Apr 17, 2026·Updated Jul 21, 2026

NVD Description

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Affected Packages (1)

github.com/hashicorp/vaultGO
From 0.11.2
Fixed in = 1.21.4

Public Exploits & PoCs1 found

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free