A critical denial-of-service (DoS) vulnerability has been identified in HashiCorp Vault and could allow malicious users to overload servers with specially crafted JSON payloads, leading to excessive resource consumption and preventing Vault instances from responding.

The vulnerability, tracked as CVE-2025-6203, affects both Vault Community and Enterprise from version 1.15.0 through several patched versions.
HashiCorp Vault: DoS Vulnerability
Vault's inspection appliances are responsible for recording each request interaction before the request is completed. A malicious user can submit a payload that meets the default max_request_size limit (32 MiB by default) but leverages nested JSON structures or excessive entries to cause excessive CPU and memory usage in the inspection process. As the JSON parser parses long string values or a high number of object entries, memory consumption increases, causing timeouts and preventing the Vault server from responding.
See also: Vulnerability in Azure Active Directory Exposes Credentials
HashiCorp has introduced new listener configuration options to further harden Vault against malicious JSON payloads. The TCP listener can now be configured with:
– max_json_depth: Maximum nesting depth for JSON objects.
– max_json_string_value_length: Maximum length for string values.
– max_json_object_entry_count: Maximum number of key/value pairs in an object.
– max_json_array_element_count: Maximum number of elements in a JSON array.
Administrators can find detailed instructions in the API documentation for listener parameters and in the Vault upgrade guide. HashiCorp says that Darrell Bethea, Ph.D., of Indeed discovered and reported the vulnerability.

HashiCorp Vault: Update to address vulnerability
To address the CVE-2025-6203 bug, customers should upgrade to one of the updated versions: Vault Community Edition 1.20.3 or Vault Enterprise editions 1.20.3, 1.19.9, 1.18.14, or 1.16.25.
The upgrade will enable built-in limits on the complexity of JSON payloads, preventing excessive recursion that causes Denial of Service. Administrators are also encouraged to review max_request_size settings and implement listener-level limits on JSON parsing.
See also: Critical Qualcomm vulnerabilities allow RCE attacks
Risks are increasing
The HashiCorp Vault DoS vulnerability highlights a broader and often underestimated challenge in cybersecurity: attacks that are not aimed at compromising data, but at disabling a critical service. In environments where Vault is used as a central system for managing secrets, certificates, and encryption keys, even a temporary unavailability can cause serious ripple effects. Consider, for example, a cloud infrastructure that relies on Vault to refresh tokens or provide dynamic databases; a successful DoS attack could “freeze” critical applications, blocking entire organizations from functioning.
It is noteworthy that this particular attack exploits the very limits of JSON parsing, a point often considered harmless or standard. This shows that attackers are constantly looking for “creative” ways to abuse the basic functionality of a service, using building blocks that would not normally be considered a threat. Thus, the incident serves as a reminder that security is not only about shielding against traditional exploits, but also about resilience against abusive login patterns.
See also: Vulnerabilities in Sitecore Experience allow remote code execution

Adding parameters like max_json_depth or max_json_object_entry_count is an important move because it gives administrators the ability to tailor Vault to the needs of their own environment. However, security is not limited to technical settings; it also requires a culture of continuous risk assessment. Organizations should prioritize simulated DoS attacks as part of resilience testing to assess their true readiness.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, the fact that the vulnerability was identified and disclosed responsibly demonstrates the importance of collaboration between academics, researchers, and companies. Thanks to such reports, software communities and businesses can prevent attacks before they become widespread. In an era where data and secret information are the “oxygen” of the digital economy, protecting the availability of services like Vault is just as critical as protecting confidentiality and integrity.
