CVE-2025-4656 Details
Description
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
A denial-of-service vulnerability has been identified in HashiCorp Vault Community and Enterprise editions. The issue arises during rekey and recovery key operations, where a Vault operator can unintentionally cancel processes, leading to service disruption. This vulnerability has been addressed in Vault Community Edition 1.20.0 and Vault Enterprise versions 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
Users can upgrade to Vault Community Edition 1.20.0 or Vault Enterprise versions 1.20.0, 1.19.6, 1.18.11, 1.17.17, or 1.16.22 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2025-11-vault-vulnerable-to-recovery-key-cancellation-denial-of-service/75570 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1088 | Synchronous Access of Remote Resource without Timeout | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hashicorp vault | >= 1.14.8, < 1.16.22 >= 1.14.8, < 1.20.0 >= 1.17.0, < 1.17.17 >= 1.18.0, < 1.18.11 >= 1.19.0, < 1.19.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 13, 2025 | Initial Analysis | [email protected] |
| Jun 25, 2025 | New CVE Received | [email protected] |