Description
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter selected rsa-, ecdsa-, or ed25519. The Transit policy creation path in builtin/logical/transit/backend.go and sdk/helper/keysutil/policy.go could reach an error path that double-unlocked a mutex while handling this invalid asymmetric derived-key combination, causing a panic, no HTTP response, process exit, and denial of service. JSON and HCL key-creation requests can express the triggering combination. This issue is fixed in version 2.5.5.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

OpenBao’s transit secrets engine contains a control‑flow flaw—CWE‑617—where a double unlock of an internal mutex occurs when an authenticated caller creates an asymmetric key with the derived flag set to true. The resulting panic terminates the server process, produces no HTTP response, and leaves the service unavailable.

Affected Systems

The issue affects OpenBao deployments running any release before 2.5.5; an authenticated user with write permission to the transit/keys/* path can exercise the weakness by submitting a JSON or HCL key‑creation request containing type rsa-, ecdsa-, or ed25519- combined with derived:true.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity problem. EPSS is < 1% and the vulnerability is not listed in CISA KEV. Exploitation requires authenticated API or UI use and sufficient write privileges; once those conditions are met the attacker can causing a denial of service. No publicly disclosed exploit is known.

Generated by OpenCVE AI on September 20, 2026 at 16:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to OpenBao 2.5.5 or a later release.
  • If an upgrade cannot be performed immediately, avoid creating transit keys with derived:true for rsa, ecdsa, or ed25519 types.
  • Monitor server logs for unexpected panics or HTTP 500 errors and verify that the transit endpoint remains responsive.

Generated by OpenCVE AI on September 20, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8w8f-r2xv-4q4j OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Openbao
Openbao openbao
Vendors & Products Openbao
Openbao openbao

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter selected rsa-, ecdsa-, or ed25519. The Transit policy creation path in builtin/logical/transit/backend.go and sdk/helper/keysutil/policy.go could reach an error path that double-unlocked a mutex while handling this invalid asymmetric derived-key combination, causing a panic, no HTTP response, process exit, and denial of service. JSON and HCL key-creation requests can express the triggering combination. This issue is fixed in version 2.5.5.
Title OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:35:58.867Z

Reserved: 2026-06-17T14:40:28.379Z

Link: CVE-2026-55776

cve-icon Vulnrichment

Updated: 2026-09-17T15:35:51.915Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:16.220

Modified: 2026-09-29T19:06:32.333

Link: CVE-2026-55776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses