Vulnerability GHSA-xp3c-3jw3-4vcr

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 days ago
September 22, 2026 at 08:36 PM UTC
OpenBao Skips Stricter Deny Policy for LIST operations
v0.1.0 - v1.1.5
v0.1.0 - v1.1.5

Summary

OpenBao Skips Stricter Deny Policy for LIST operations

Details

Impact

When a policy operator has written capabilities = ["deny"] on a path with a trailing wildcard but allowed a broader list operation (e.g., a deny on secrets/metadata/restricted/* but allowed list on secrets/metadata/*), OpenBao would incorrectly allow the operation. This did not impact other operation types.

Patches

This has been patched in OpenBao v2.6.0.

Timeline

Published
5 days ago
September 22, 2026 at 08:36 PM UTC
Last Modified
5 days ago
September 22, 2026 at 09:00 PM UTC