CVE-2018-19786: Hashicorp Vault
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
Affected products
- Hashicorp Vault: before 1.0.0 (fixed in 1.0.0)
Published 2018-12-05. Last modified 2026-06-17.