blob: 3a3a55bcd479d27a5a2bf0b2ad6eeeafd257df30 [file] [log] [blame]
id: GO-2025-4071
modules:
- module: github.com/hashicorp/vault
versions:
- introduced: 1.20.3
- fixed: 1.21.0
vulnerable_at: 1.21.0-rc1
summary: |-
Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when
processing JSON in github.com/hashicorp/vault
cves:
- CVE-2025-12044
ghsas:
- GHSA-vp5w-xcfc-73wf
references:
- advisory: https://github.com/advisories/GHSA-vp5w-xcfc-73wf
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-12044
- fix: https://github.com/hashicorp/vault/commit/b19e74c29a33ed2a99fc01626104db1a49345df3
- fix: https://github.com/hashicorp/vault/commit/eedc2b7426f30e57e306229ce697ce81e203ab89
- web: https://discuss.hashicorp.com/t/hcsec-2025-31-vault-vulnerable-to-denial-of-service-due-to-rate-limit-regression/76710
source:
id: GHSA-vp5w-xcfc-73wf
created: 2025-10-28T17:26:42.418022014Z
review_status: UNREVIEWED