CVE-2025-6004: Hashicorp Vault

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

Affected products

  • Hashicorp Vault: from 1.13.0, before 1.16.23 (fixed in 1.16.23); from 1.13.0, before 1.20.1 (fixed in 1.20.1); from 1.17.0, before 1.18.12 (fixed in 1.18.12); from 1.19.0, before 1.19.7 (fixed in 1.19.7); version 1.20.0 only

Published 2025-08-01. Last modified 2026-06-17.