CVE-2025-4166

Name
CVE-2025-4166
Description
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security@hashicorp.com https://discuss.hashicorp.com/t/hcsec-2025-09-vault-may-expose-sensitive-information-in-error-logs-when-processing-malformed-data-with-the-kv-v2-plugin

Match rules

CPE URI Source package Min version Max version
vault >= 0.3.0 < 1.19.2
vault-enterprise >= 0.10.0 < 1.19.2
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* vault >= 0.3.0 < 1.16.20
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* vault >= 0.3.0 < 1.19.3
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* vault >= 1.17.0 < 1.17.16
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* vault >= 1.18.0 < 1.18.9
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* vault >= 1.19.0 < 1.19.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vault edge-community 1.14.0-r0 Mike Crute <mike@crute.us> possibly vulnerable
vault edge-community 1.13.2-r0 Mike Crute <mike@crute.us> possibly vulnerable
vault edge-community 1.11.4-r0 Gennady Feldman <gena01@gmail.com> possibly vulnerable
vault edge-community 1.9.4-r0 Gennady Feldman <gena01@gmail.com> possibly vulnerable
vault edge-community 1.7.2-r0 Gennady Feldman <gena01@gmail.com> possibly vulnerable
vault edge-community 1.7.1-r0 Gennady Feldman <gena01@gmail.com> possibly vulnerable
vault edge-community 1.6.3-r0 None possibly vulnerable
vault edge-community 1.5.7-r0 None possibly vulnerable
vault edge-community 1.5.6-r0 None possibly vulnerable
vault edge-community 1.5.4-r0 None possibly vulnerable
vault edge-community 1.4.3-r0 None possibly vulnerable
openbao edge-community 2.2.2-r0 Kevin Daudt <kdaudt@alpinelinux.org> fixed
openbao 3.22-community 2.2.2-r0 None fixed