Vault Vulnerable to Recovery Key Cancellation Denial of Service
Published Jun 25, 2025
3.1
LOWCVSS 3.1
EPSS 0.27%
Description
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
Affected products
-
- Version 1.14.8StatusaffectedConstraints<1.20.0
- Version
-
- Version 1.14.8StatusaffectedConstraints<1.20.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HashiCorp | Vault | unaffected |
| ||||||
| HashiCorp | Vault Enterprise | unaffected |
|
No data.
Red Hat Openshift Data Foundation 4
odf4/cephcsi-rhel9
Fix deferred
Red Hat Openshift Data Foundation 4
odf4/mcg-cli-rhel9
Fix deferred
Red Hat Openshift Data Foundation 4
odf4/mcg-rhel9-operator
Fix deferred
Red Hat Openshift Data Foundation 4
odf4/odf-cli-rhel9
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/client-server-rhel9
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/fulcio-rhel9
Fix deferred
cert-manager Operator for Red Hat OpenShift
cert-manager/cert-manager-operator-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Fix deferred | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-cli-rhel9 | Fix deferred | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-rhel9-operator | Fix deferred | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-cli-rhel9 | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/client-server-rhel9 | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/fulcio-rhel9 | Fix deferred | n/a |
| cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Fix deferred | n/a |
github.com/hashicorp/vault
Go
Introduced 1.14.8 Fixed 1.20.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/vault | 1.14.8 | 1.20.0 |
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2025-4656 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2374792 Issue Tracking
- https://discuss.hashicorp.com/t/hcsec-2025-11-vault-vulnerable-to-recovery-key-cancellation-denial-of-service/75570 Vendor Advisory
- https://github.com/advisories/GHSA-fhc2-8qx8-6vj7 Advisory
- https://github.com/hashicorp/vault/pull/30794
- https://nvd.nist.gov/vuln/detail/CVE-2025-4656
- https://www.cve.org/CVERecord?id=CVE-2025-4656
Change history (0)
No recorded changes yet.