CVE-2025-6011: Hashicorp Vault

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

Affected products

  • Hashicorp Vault: before 1.16.23 (fixed in 1.16.23); before 1.20.1 (fixed in 1.20.1); from 1.17.0, before 1.18.12 (fixed in 1.18.12); from 1.19.0, before 1.19.7 (fixed in 1.19.7); version 1.20.0 only

Published 2025-08-01. Last modified 2026-06-17.