GHSA-hwc3-3qh6-r4gg
GitHub Security Advisory
HashiCorp Vault's PKI mount vulnerable to denial of service
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.
Affected Packages
Go
github.com/hashicorp/vault
Affected versions:
0
(fixed in 1.11.9)
Go
github.com/hashicorp/vault
Affected versions:
1.12.0
(fixed in 1.12.5)
Go
github.com/hashicorp/vault
Affected versions:
1.13.0
(fixed in 1.13.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.