CVE-2025-4656: Hashicorp Vault
Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
Affected products
- Hashicorp Vault: from 1.14.8, before 1.16.22 (fixed in 1.16.22); from 1.14.8, before 1.20.0 (fixed in 1.20.0); from 1.17.0, before 1.17.17 (fixed in 1.17.17); from 1.18.0, before 1.18.11 (fixed in 1.18.11); from 1.19.0, before 1.19.6 (fixed in 1.19.6)
Published 2025-06-25. Last modified 2026-06-17.