Impact
OpenBao’s transit secrets engine contains a control‑flow flaw—CWE‑617—where a double unlock of an internal mutex occurs when an authenticated caller creates an asymmetric key with the derived flag set to true. The resulting panic terminates the server process, produces no HTTP response, and leaves the service unavailable.
Affected Systems
The issue affects OpenBao deployments running any release before 2.5.5; an authenticated user with write permission to the transit/keys/* path can exercise the weakness by submitting a JSON or HCL key‑creation request containing type rsa-, ecdsa-, or ed25519- combined with derived:true.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity problem. EPSS is < 1% and the vulnerability is not listed in CISA KEV. Exploitation requires authenticated API or UI use and sufficient write privileges; once those conditions are met the attacker can causing a denial of service. No publicly disclosed exploit is known.
OpenCVE Enrichment
Github GHSA