HashiCorp recently disclosed two critical vulnerabilities in Vault — the tool used by thousands of enterprises to manage secrets, keys, and certificates. The security flaws, listed as CVE -2025-12044 and CVE-2025-11621 , affect both the Community and Enterprise editions and require immediate attention from infrastructure administrators and security teams.

What exactly threatens the Vault
Vault acts as a “central vault” for secrets across cloud and hybrid environments — from API keys to TLS certificates. The two vulnerabilities reveal that errors in resource management and authentication caching can lead to either a breach of authentication checks or a DoS attack that will take down critical services.
DoS via JSON payload exploitation
CVE-2025-12044 concerns the processing of complex or large JSON payloads. A previous fix failed to fully block the attack. In the affected versions, Vault applies rate limits after parsing incoming JSON requests (whereas it should have done so before), allowing attackers to flood the system with large, valid payloads below the max_request_size threshold.
See also: Critical Dell Storage Manager vulnerabilities allow compromise
Operators set tunable rate limits and resource quotas in Vault to prevent abuse, but this flaw allows repeated requests to consume excessive CPU and memory, resulting in service outages or delays that prevent access to keys and secrets.
Bypass authentication
CVE -2025-11621 affects Vault's AWS Auth method — and has even more serious consequences.
This method automates the retrieval of tokens for the main IAM parameters and EC2 instances, but an error in the caching logic does not validate the AWS account ID.
If the bound_principal_iam role matches all accounts or uses wildcards, an attacker from a different account can impersonate a legitimate user, leading to unauthorized access, data exposure, and privilege escalation.
A similar issue affects EC2 authentication, where cache lookups only check AMI IDs, not account IDs, allowing cross-account attacks.
Which versions are affected and what is the solution?
The vulnerabilities span a wide range of versions: from older builds to recent minor versions of Vault. HashiCorp has issued patches.

Specifically, the CVE-2025-12044 affects versions 1.20.3 to 1.20.4 of Vault Community Edition, with fixes available in version 1.21.0.
See also: Pwn2Own Ireland 2025: $1,024,750 in prizes for 73 zero-days
For Vault Enterprise, the affected versions cover versions 1.20.3 to 1.20.4, 1.19.9 to 1.19.10, 1.18.14 to 1.18.15, and 1.16.25 to 1.16.26, which have been updated to versions 1.21.0, 1.20.5, 1.19.11, and 1.16.27.
The CVE-2025-11621 vulnerability affects Vault Community Edition from 0.6.0 to 1.20.4 (fixed in version 1.21.0) and Vault Enterprise from 0.6.0 to 1.20.4, plus versions 1.19.10, 1.18.15, and 1.16.26 (fixed in versions 1.21.0, 1.20.5, 1.19.11, and 1.16.27).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What can administrators do now?
If immediate upgrade is not possible, there are temporary risk mitigation measures:
- Remove wildcards from bound_principal_iam.
- Enable strict account ID checks for AWS and EC2 authentication.
- Increase monitoring and logging for unusual JSON requests or repeated heavy loads.
- Apply additional rate limits and resource restrictions to endpoints that parse JSON.
Factors vulnerable to broader attacks
The importance of Vault in modern infrastructure platforms makes its exploitation particularly critical: successful authentication bypass can lead to access to secrets that open the door to other systems, while DoS on Vault instances can freeze deployment pipelines, services, and certificate renewals.
See also: Multiple flaws in Oracle VM VirtualBox

Lesson and next steps
These incidents are a reminder that secrets security requires not only specific fixes but also defense strategies: stricter IAM policies, configuration audits, continuous monitoring, and prompt patching. Collaboration with independent security researchers and auditing code paths involving caching and parsing are essential to avoid similar issues in the future.
The disclosure of CVE-2025-12044 and CVE-2025-11621 is a clear reminder: security foundations — like Vault — need constant vigilance and rapid fixes to remain reliable.
