If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Apr 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
|
| Vendors & Products |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
Fri, 17 Apr 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16. | |
| Title | Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-04-17T03:00:47.561Z
Reserved: 2026-03-20T17:47:40.835Z
Link: CVE-2026-4525
No data.
Status : Received
Published: 2026-04-17T04:16:09.997
Modified: 2026-04-17T04:16:09.997
Link: CVE-2026-4525
No data.
OpenCVE Enrichment
Updated: 2026-04-17T04:30:09Z