Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8185


Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself. This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.


Published

2024-10-31T16:15:06.267

Last Modified

2025-11-13T17:40:36.950

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-636

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hashicorp vault < 1.16.12 Yes
Application hashicorp vault < 1.18.1 Yes
Application hashicorp vault < 1.17.8 Yes
Application hashicorp vault 1.18.0 Yes
Application openbao openbao < 2.0.3 Yes

References