CVE-2020-25594: Hashicorp Vault

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.

Affected products

  • Hashicorp Vault: before 1.5.7 (fixed in 1.5.7); from 1.6.0, before 1.6.2 (fixed in 1.6.2)

Published 2021-02-01. Last modified 2026-06-17.