CVE-2025-6015: Hashicorp Vault
Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Affected products
- Hashicorp Vault: from 1.10.0, before 1.16.23 (fixed in 1.16.23); from 1.10.0, before 1.20.1 (fixed in 1.20.1); from 1.17.0, before 1.18.12 (fixed in 1.18.12); from 1.19.0, before 1.19.7 (fixed in 1.19.7); version 1.20.0 only
Published 2025-08-01. Last modified 2026-06-17.