CVE-2025-4656: CWE-1088: Synchronous Access of Remote Resource without Timeout in HashiCorp Vault
CVE-2025-4656 is a low-severity vulnerability in HashiCorp Vault affecting rekey and recovery key operations. It involves synchronous access of a remote resource without a timeout, which can lead to denial of service caused by uncontrolled cancellation by a Vault operator. The vulnerability has been fixed in Vault Community Edition 1.20.0 and several Enterprise versions.
AI Analysis
Technical Summary
CVE-2025-4656 (CWE-1088) is a vulnerability in HashiCorp Vault where synchronous access to a remote resource during rekey and recovery key operations lacks a timeout mechanism. This flaw allows a Vault operator to cause a denial of service through uncontrolled cancellation of these operations. The issue affects specific versions of Vault and has been addressed in Vault Community Edition 1.20.0 and Enterprise versions 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
Potential Impact
The vulnerability can cause a denial of service condition by allowing an operator to cancel rekey and recovery key operations without control, potentially disrupting Vault's key management processes. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Apply the official fixes by upgrading to Vault Community Edition 1.20.0 or the corresponding patched Enterprise versions (1.20.0, 1.19.6, 1.18.11, 1.17.17, or 1.16.22). No other mitigation is indicated.
CVE-2025-4656: CWE-1088: Synchronous Access of Remote Resource without Timeout in HashiCorp Vault
Description
CVE-2025-4656 is a low-severity vulnerability in HashiCorp Vault affecting rekey and recovery key operations. It involves synchronous access of a remote resource without a timeout, which can lead to denial of service caused by uncontrolled cancellation by a Vault operator. The vulnerability has been fixed in Vault Community Edition 1.20.0 and several Enterprise versions.
CVSS v3.1
Score 3.1low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-4656 (CWE-1088) is a vulnerability in HashiCorp Vault where synchronous access to a remote resource during rekey and recovery key operations lacks a timeout mechanism. This flaw allows a Vault operator to cause a denial of service through uncontrolled cancellation of these operations. The issue affects specific versions of Vault and has been addressed in Vault Community Edition 1.20.0 and Enterprise versions 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
Potential Impact
The vulnerability can cause a denial of service condition by allowing an operator to cancel rekey and recovery key operations without control, potentially disrupting Vault's key management processes. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Apply the official fixes by upgrading to Vault Community Edition 1.20.0 or the corresponding patched Enterprise versions (1.20.0, 1.19.6, 1.18.11, 1.17.17, or 1.16.22). No other mitigation is indicated.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- HashiCorp
- Date Reserved
- 2025-05-13T15:30:55.244Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 685c25a8c6576a567aed85d3
Added to database: 06/25/2025, 16:36:56 UTC
Last enriched: 09/08/2026, 13:08:42 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 112
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.