LOW 3.7 Go

Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users

GHSA-mwgr-84fv-3jh9 · BIT-vault-2025-6011 · CVE-2025-6011 · GO-2025-3839

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

Ready to move

Start Securing

Free, no credit card | First findings in minutes