LOW 3.1 Go
Vault Community Edition rekey and recovery key operations can cause denial of service
GHSA-fhc2-8qx8-6vj7 · BIT-vault-2025-4656 · CVE-2025-4656 · GO-2025-3788
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
Ready to move
Start Securing
Free, no credit card | First findings in minutes