Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4166


Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.


Published

2025-05-02T15:15:50.313

Last Modified

2025-08-12T01:44:28.067

Status

Undergoing Analysis

Source

[email protected]

Severity

CVSSv3.1: 4.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-209

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hashicorp vault < 1.16.20 Yes
Application hashicorp vault < 1.19.3 Yes
Application hashicorp vault < 1.17.16 Yes
Application hashicorp vault < 1.18.9 Yes
Application hashicorp vault < 1.19.3 Yes

References