Vulnerabilities in openbao

32 results
Vexday analysis

OpenBao possui 21 vulnerabilidades no registro com 3 críticas, mas nenhuma sob exploração ativa conhecida. A fraqueza predominante (CWE-532: Log Information Disclosure) sugere exposição de dados sensíveis em logs, risco moderado para ambientes com auditoria rigorosa. O volume reduzido de descobertas recentes (1 em 90 dias) indica maturidade relativa do produto, mas exige atenção contínua às críticas catalogadas.

CVE-2025-59043HIGHOpenBao vulnerable to denial of service via malicious JSON request processingEPSS 0.7%CVE-2026-55776MEDIUMOpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key typesEPSS 0.5%CVE-2026-55770MEDIUMOpenBao: LDAPi ldaputil (wrong escape func)EPSS 0.4%CVE-2026-55774LOWOpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808EPSS 0.4%CVE-2026-33757CRITICALOpenBao lacks user confirmation for OIDC direct callback modeEPSS 0.4%CVE-2025-54997CRITICALOpenBao: Privileged Operator May Execute Code on the Underlying HostEPSS 0.4%CVE-2025-52894MEDIUMOpenBao Vulnerable to Unauthenticated Rekey Operation CancellationEPSS 0.4%CVE-2026-46405MEDIUMOpenBao's Kerberos Auth Method Accumulates Unaccessible TokensEPSS 0.4%CVE-2025-64761HIGHOpenBao Privileged Operator Identity Group Root EscalationEPSS 0.4%CVE-2026-55775LOWOpenBao's System Backend allows Unauthorized Management of the containing NamespaceEPSS 0.4%CVE-2025-62705MEDIUMOpenBao and Vault Leak []byte Fields in Audit LogsEPSS 0.3%CVE-2025-62513MEDIUMOpenBao leaks HTTPRawBody in Audit LogsEPSS 0.3%CVE-2025-54996HIGHOpenBao Root Namespace Operator May Elevate Token PrivilegesEPSS 0.3%CVE-2026-45808HIGHOpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACLEPSS 0.3%CVE-2025-52893MEDIUMOpenBao May Leak Sensitive Information in Logs When Processing Malformed DataEPSS 0.3%CVE-2026-40264LOWOpenBao's Token Store Allows Cross-Namespace Renewal, RevocationEPSS 0.3%CVE-2026-33758CRITICALOpenBao has Reflected XSS in its OIDC authentication error messageEPSS 0.3%CVE-2026-71543HIGHOpenBao's Templated Policies Allow Privilege Escalation via Wildcard CharactersEPSS 0.2%CVE-2025-59048HIGHOpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth MethodEPSS 0.2%CVE-2026-42186LOWOpenBao's Namespace Deletion May Not Delete Data ProperlyEPSS 0.2%