HomeSecurityHashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass

HashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass

HashiCorp recently disclosed two critical vulnerabilities in Vault — the tool used by thousands of enterprises to manage secrets, keys, and certificates. The security flaws, listed as CVE -2025-12044 and CVE-2025-11621 , affect both the Community and Enterprise editions and require immediate attention from infrastructure administrators and security teams.

HashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass

What exactly threatens the Vault

Vault acts as a “central vault” for secrets across cloud and hybrid environments — from API keys to TLS certificates. The two vulnerabilities reveal that errors in resource management and authentication caching can lead to either a breach of authentication checks or a DoS attack that will take down critical services.

DoS via JSON payload exploitation

CVE-2025-12044 concerns the processing of complex or large JSON payloads. A previous fix failed to fully block the attack. In the affected versions, Vault applies rate limits after parsing incoming JSON requests (whereas it should have done so before), allowing attackers to flood the system with large, valid payloads below the max_request_size threshold.

See also: Critical Dell Storage Manager vulnerabilities allow compromise

Operators set tunable rate limits and resource quotas in Vault to prevent abuse, but this flaw allows repeated requests to consume excessive CPU and memory, resulting in service outages or delays that prevent access to keys and secrets.

Bypass authentication

CVE -2025-11621 affects Vault's AWS Auth method — and has even more serious consequences.

This method automates the retrieval of tokens for the main IAM parameters and EC2 instances, but an error in the caching logic does not validate the AWS account ID.

If the bound_principal_iam role matches all accounts or uses wildcards, an attacker from a different account can impersonate a legitimate user, leading to unauthorized access, data exposure, and privilege escalation.

A similar issue affects EC2 authentication, where cache lookups only check AMI IDs, not account IDs, allowing cross-account attacks.

Which versions are affected and what is the solution?

The vulnerabilities span a wide range of versions: from older builds to recent minor versions of Vault. HashiCorp has issued patches.

HashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass

Specifically, the CVE-2025-12044 affects versions 1.20.3 to 1.20.4 of Vault Community Edition, with fixes available in version 1.21.0.

See also: Pwn2Own Ireland 2025: $1,024,750 in prizes for 73 zero-days

For Vault Enterprise, the affected versions cover versions 1.20.3 to 1.20.4, 1.19.9 to 1.19.10, 1.18.14 to 1.18.15, and 1.16.25 to 1.16.26, which have been updated to versions 1.21.0, 1.20.5, 1.19.11, and 1.16.27.

The CVE-2025-11621 vulnerability affects Vault Community Edition from 0.6.0 to 1.20.4 (fixed in version 1.21.0) and Vault Enterprise from 0.6.0 to 1.20.4, plus versions 1.19.10, 1.18.15, and 1.16.26 (fixed in versions 1.21.0, 1.20.5, 1.19.11, and 1.16.27).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What can administrators do now?

If immediate upgrade is not possible, there are temporary risk mitigation measures:

  • Remove wildcards from bound_principal_iam.
  • Enable strict account ID checks for AWS and EC2 authentication.
  • Increase monitoring and logging for unusual JSON requests or repeated heavy loads.
  • Apply additional rate limits and resource restrictions to endpoints that parse JSON.

Factors vulnerable to broader attacks

The importance of Vault in modern infrastructure platforms makes its exploitation particularly critical: successful authentication bypass can lead to access to secrets that open the door to other systems, while DoS on Vault instances can freeze deployment pipelines, services, and certificate renewals.

See also: Multiple flaws in Oracle VM VirtualBox

HashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass

Lesson and next steps

These incidents are a reminder that secrets security requires not only specific fixes but also defense strategies: stricter IAM policies, configuration audits, continuous monitoring, and prompt patching. Collaboration with independent security researchers and auditing code paths involving caching and parsing are essential to avoid similar issues in the future.

The disclosure of CVE-2025-12044 and CVE-2025-11621 is a clear reminder: security foundations — like Vault — need constant vigilance and rapid fixes to remain reliable.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS