Vulnerabilidades en openbao
32 resultadosAnálisis Vexday
OpenBao possui 21 vulnerabilidades no registro com 3 críticas, mas nenhuma sob exploração ativa conhecida. A fraqueza predominante (CWE-532: Log Information Disclosure) sugere exposição de dados sensíveis em logs, risco moderado para ambientes com auditoria rigorosa. O volume reduzido de descobertas recentes (1 em 90 dias) indica maturidade relativa do produto, mas exige atenção contínua às críticas catalogadas.
CVE-2025-59043HIGHOpenBao vulnerable to denial of service via malicious JSON request processingEPSS 0.7%CVE-2026-46405MEDIUMOpenBao's Kerberos Auth Method Accumulates Unaccessible TokensEPSS 0.6%CVE-2026-55776MEDIUMOpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key typesEPSS 0.6%CVE-2026-33757CRITICALOpenBao lacks user confirmation for OIDC direct callback modeEPSS 0.6%CVE-2026-55774LOWOpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808EPSS 0.6%CVE-2026-55770MEDIUMOpenBao: LDAPi ldaputil (wrong escape func)EPSS 0.5%CVE-2026-63132CRITICALOpenBao's Recovery Mode Vulnerable To Token Leakage via Timing AttackEPSS 0.5%CVE-2026-55775LOWOpenBao's System Backend allows Unauthorized Management of the containing NamespaceEPSS 0.5%CVE-2026-33758CRITICALOpenBao has Reflected XSS in its OIDC authentication error messageEPSS 0.4%CVE-2026-42186LOWOpenBao's Namespace Deletion May Not Delete Data ProperlyEPSS 0.4%CVE-2026-45808HIGHOpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACLEPSS 0.4%CVE-2026-71543HIGHOpenBao's Templated Policies Allow Privilege Escalation via Wildcard CharactersEPSS 0.4%CVE-2026-39946MEDIUMOpenBao allows SQL Injection in PostgreSQL database secrets engineEPSS 0.4%CVE-2025-54997CRITICALOpenBao: Privileged Operator May Execute Code on the Underlying HostEPSS 0.4%CVE-2025-52894MEDIUMOpenBao Vulnerable to Unauthenticated Rekey Operation CancellationEPSS 0.4%CVE-2026-40264LOWOpenBao's Token Store Allows Cross-Namespace Renewal, RevocationEPSS 0.4%CVE-2025-64761HIGHOpenBao Privileged Operator Identity Group Root EscalationEPSS 0.4%CVE-2026-63131MEDIUMOpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific deny rule (unported Vault v2.0.3 fix)EPSS 0.4%CVE-2025-62705MEDIUMOpenBao and Vault Leak []byte Fields in Audit LogsEPSS 0.3%CVE-2026-39396LOWOpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)EPSS 0.3%