HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads
High severity
GitHub Reviewed
Published
Aug 28, 2025
to the GitHub Advisory Database
•
Updated Aug 29, 2025
Description
Published by the National Vulnerability Database
Aug 28, 2025
Published to the GitHub Advisory Database
Aug 28, 2025
Reviewed
Aug 29, 2025
Last updated
Aug 29, 2025
A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unresponsive. This vulnerability, CVE-2025-6203, is fixed in Vault Community Edition 1.20.3 and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25.
References