CVE-2025-6014: Hashicorp Vault
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Affected products
- Hashicorp Vault: before 1.16.23 (fixed in 1.16.23); before 1.20.1 (fixed in 1.20.1); from 1.17.0, before 1.18.12 (fixed in 1.18.12); from 1.19.0, before 1.19.7 (fixed in 1.19.7); version 1.20.0 only
Published 2025-08-01. Last modified 2026-06-17.