vciy

CVEs we hold for Openbao

Records whose assigning authority named Openbao as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-55776OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key typesopenbao
CVE-2026-55775OpenBao's System Backend allows Unauthorized Management of the containing Namespaceopenbao
CVE-2026-55774OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of…openbao
CVE-2026-55770OpenBao: LDAPi ldaputil (wrong escape func)openbao
CVE-2026-46405OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokensopenbao
CVE-2026-46358OpenBao's Inline Auth Incorrectly Redacted Headersopenbao
CVE-2026-45808OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACLopenbao
CVE-2026-42186OpenBao's Namespace Deletion May Not Delete Data Properlyopenbao
CVE-2026-40264OpenBao's Token Store Allows Cross-Namespace Renewal, Revocationopenbao
CVE-2026-39946OpenBao allows SQL Injection in PostgreSQL database secrets engineopenbao
CVE-2026-39396OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)openbao
CVE-2026-39388OpenBao's Certificate Authentication Allows Token Renewal With Different Certificateopenbao
CVE-2026-33758OpenBao has Reflected XSS in its OIDC authentication error messageopenbao
CVE-2026-33757OpenBao lacks user confirmation for OIDC direct callback modeopenbao
CVE-2025-64761OpenBao Privileged Operator Identity Group Root Escalationopenbao
CVE-2025-62705OpenBao and Vault Leak []byte Fields in Audit Logsopenbao
CVE-2025-62513OpenBao leaks HTTPRawBody in Audit Logsopenbao
CVE-2025-59048OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Methodopenbao-plugins
CVE-2025-59043OpenBao vulnerable to denial of service via malicious JSON request processingopenbao
CVE-2025-55003OpenBao Login MFA Bypasses Rate Limiting and TOTP Token Reuseopenbao
CVE-2025-55001OpenBao LDAP MFA Enforcement Bypass When Using Username As Aliasopenbao
CVE-2025-55000OpenBao TOTP Secrets Engine Enables Code Reuseopenbao
CVE-2025-54999OpenBao: Timing Side-Channel in Userpass Auth Methodopenbao
CVE-2025-54998OpenBao Userpass and LDAP User Lockout Bypassopenbao
CVE-2025-54997OpenBao: Privileged Operator May Execute Code on the Underlying Hostopenbao
CVE-2025-54996OpenBao Root Namespace Operator May Elevate Token Privilegesopenbao
CVE-2025-52894OpenBao Vulnerable to Unauthenticated Rekey Operation Cancellationopenbao
CVE-2025-52893OpenBao May Leak Sensitive Information in Logs When Processing Malformed Dataopenbao

28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.