A AegiFlow
HIGHCVSS 7.5EPSS 0.4%

CVE-2026-4525

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

Published
2026-04-17
Modified
2026-07-21
EPSS percentile
33%
Aliases
GHSA-72gw-fmmr-c4r4
Sources
github-advisory

Summary

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/hashicorp/vault

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.