Vulnerability GHSA-xp3c-3jw3-4vcr
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 days ago
September 22, 2026 at 08:36 PM UTC
OpenBao Skips Stricter Deny Policy for LIST operations
v0.1.0 - v1.1.5
v0.1.0 - v1.1.5
Summary
OpenBao Skips Stricter Deny Policy for LIST operations
Details
Impact
When a policy operator has written capabilities = ["deny"] on a path with a trailing wildcard but allowed a broader list operation (e.g., a deny on secrets/metadata/restricted/* but allowed list on secrets/metadata/*), OpenBao would incorrectly allow the operation. This did not impact other operation types.
Patches
This has been patched in OpenBao v2.6.0.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
5 days ago
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
v0.1.0 - v1.1.5 GHSA-34fc-gh42-pj53
v0.1.0 - v1.1.5 GHSA-34fc-gh42-pj53
High Risk
5 days ago
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
v0.1.0 - v1.1.5 GHSA-59w7-v8rr-pr4p
v0.1.0 - v1.1.5 GHSA-59w7-v8rr-pr4p
Low Risk
5 days ago
OpenBao Agent Writes Secrets to Stdout
v0.1.0 - v1.1.5 GHSA-444v-8vxr-p36h
v0.1.0 - v1.1.5 GHSA-444v-8vxr-p36h
Unknown
3 months ago
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL in github.com/openbao/openbao
v0.1.0 - v1.15.5 GO-2026-5657
v0.1.0 - v1.15.5 GO-2026-5657
Unknown
3 months ago
OpenBao's Namespace Deletion May Not Delete Data Properly in github.com/openbao/openbao
<0.0.0-20260420173541-6d2e0506e2b4 GO-2026-5674
<0.0.0-20260420173541-6d2e0506e2b4 GO-2026-5674
Impacted packages
Timeline
Published
5 days ago
September 22, 2026 at 08:36 PM UTC
Last Modified
5 days ago
September 22, 2026 at 09:00 PM UTC