Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [+HCSEC-2025-24+|https://discuss.hashicorp.com/t/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads/76393]  which allowed for processing JSON payloads before applying rate limits. This vulnerability, CVE-2025-12044, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.16.27, 1.19.11, 1.20.5, and 1.21.0.

Project Subscriptions

Vendors Products
Hashicorp Subscribe
Vault Enterprise Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vp5w-xcfc-73wf Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Dec 2025 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*

Fri, 14 Nov 2025 00:15:00 +0000


Fri, 24 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp vault
Hashicorp vault Enterprise
Vendors & Products Hashicorp
Hashicorp vault
Hashicorp vault Enterprise

Thu, 23 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 19:30:00 +0000

Type Values Removed Values Added
Description Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [+HCSEC-2025-24+|https://discuss.hashicorp.com/t/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads/76393]  which allowed for processing JSON payloads before applying rate limits. This vulnerability, CVE-2025-12044, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.16.27, 1.19.11, 1.20.5, and 1.21.0.
Title Vault Vulnerable to Denial of Service Due to Rate Limit Regression
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2025-10-23T20:00:16.601Z

Reserved: 2025-10-21T19:12:21.827Z

Link: CVE-2025-12044

cve-icon Vulnrichment

Updated: 2025-10-23T20:00:13.049Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-23T20:15:37.607

Modified: 2025-12-23T20:26:03.503

Link: CVE-2025-12044

cve-icon Redhat

Severity : Important

Publid Date: 2025-10-23T19:15:16Z

Links: CVE-2025-12044 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-10-24T10:16:49Z

Weaknesses