Skip to content

x/vulndb: potential Go vuln in github.com/hashicorp/vault: GHSA-qv3p-fmv3-9hww #3841

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-qv3p-fmv3-9hww references a vulnerability in the following Go modules:

Module
github.com/hashicorp/vault

Description:
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/hashicorp/vault
      versions:
        - fixed: 1.20.1
      vulnerable_at: 1.20.0
summary: Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault
cves:
    - CVE-2025-6014
ghsas:
    - GHSA-qv3p-fmv3-9hww
references:
    - advisory: https://github.com/advisories/GHSA-qv3p-fmv3-9hww
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-6014
    - web: https://discuss.hashicorp.com/t/hcsec-2025-17-vault-totp-secrets-engine-code-reuse/76036
source:
    id: GHSA-qv3p-fmv3-9hww
    created: 2025-08-01T22:01:19.161288401Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions