GHSA-j2rp-gmqv-frhv
GitHub Security Advisory
HashiCorpVault does not correctly validate OCSP responses
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. Fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.
Affected Packages
Go
github.com/hashicorp/vault
Affected versions:
0
(fixed in 1.16.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.