LOW 3.7 Go
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
GHSA-mwgr-84fv-3jh9 · BIT-vault-2025-6011 · CVE-2025-6011 · GO-2025-3839
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Ready to move
Start Securing
Free, no credit card | First findings in minutes