Vulnerability GHSA-34fc-gh42-pj53
Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
5 days ago
September 22, 2026 at 08:36 PM UTC
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
v0.1.0 - v1.1.5
v0.1.0 - v1.1.5
Summary
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
Details
Impact
When running in the highly privileged recovery mode, OpenBao was vulnerable to a timing attack against the single recovery token. This allowed an attacker to extract the recovery token and use it to perform operations against the OpenBao instance, including reading or modification of data.
Patches
This has been patched in OpenBao v2.6.0.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
5 days ago
OpenBao Skips Stricter Deny Policy for LIST operations
v0.1.0 - v1.1.5 GHSA-xp3c-3jw3-4vcr
v0.1.0 - v1.1.5 GHSA-xp3c-3jw3-4vcr
High Risk
5 days ago
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
v0.1.0 - v1.1.5 GHSA-59w7-v8rr-pr4p
v0.1.0 - v1.1.5 GHSA-59w7-v8rr-pr4p
Low Risk
5 days ago
OpenBao Agent Writes Secrets to Stdout
v0.1.0 - v1.1.5 GHSA-444v-8vxr-p36h
v0.1.0 - v1.1.5 GHSA-444v-8vxr-p36h
Unknown
3 months ago
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL in github.com/openbao/openbao
v0.1.0 - v1.15.5 GO-2026-5657
v0.1.0 - v1.15.5 GO-2026-5657
Unknown
3 months ago
OpenBao's Namespace Deletion May Not Delete Data Properly in github.com/openbao/openbao
<0.0.0-20260420173541-6d2e0506e2b4 GO-2026-5674
<0.0.0-20260420173541-6d2e0506e2b4 GO-2026-5674
Impacted packages
Timeline
Published
5 days ago
September 22, 2026 at 08:36 PM UTC
Last Modified
5 days ago
September 22, 2026 at 09:00 PM UTC