CVE-2025-6011: CWE-203: Observable Discrepancy in HashiCorp Vault
CVE-2025-6011 is a timing side channel vulnerability in HashiCorp Vault's userpass authentication method that allows an attacker to distinguish between existing and non-existing usernames. This could enable username enumeration. The issue is fixed in Vault Community Edition 1.20.1 and Vault Enterprise versions 1.20.1, 1.19.7, 1.18.12, and 1.16.23. The vulnerability has a low severity score of 3.7 and does not impact confidentiality, integrity, or availability beyond username disclosure.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-6011) involves a timing side channel in the userpass authentication method of HashiCorp Vault and Vault Enterprise. An attacker can exploit timing differences to determine whether a username exists in the system, effectively allowing enumeration of valid usernames. The flaw is categorized under CWE-203 (Observable Discrepancy). Official patches addressing this issue are available in Vault Community Edition 1.20.1 and Vault Enterprise versions 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Potential Impact
The primary impact is the potential disclosure of valid usernames through timing analysis, which could aid attackers in further targeted attacks. There is no direct impact on data confidentiality, integrity, or availability. The vulnerability is rated low severity with a CVSS score of 3.7, reflecting limited impact.
Mitigation Recommendations
Apply the official patches provided by HashiCorp: upgrade to Vault Community Edition 1.20.1 or Vault Enterprise 1.20.1, 1.19.7, 1.18.12, or 1.16.23. These versions contain fixes that eliminate the timing side channel vulnerability. No additional mitigation steps are indicated by the vendor advisory.
CVE-2025-6011: CWE-203: Observable Discrepancy in HashiCorp Vault
Description
CVE-2025-6011 is a timing side channel vulnerability in HashiCorp Vault's userpass authentication method that allows an attacker to distinguish between existing and non-existing usernames. This could enable username enumeration. The issue is fixed in Vault Community Edition 1.20.1 and Vault Enterprise versions 1.20.1, 1.19.7, 1.18.12, and 1.16.23. The vulnerability has a low severity score of 3.7 and does not impact confidentiality, integrity, or availability beyond username disclosure.
CVSS v3.1
Score 3.7low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-6011) involves a timing side channel in the userpass authentication method of HashiCorp Vault and Vault Enterprise. An attacker can exploit timing differences to determine whether a username exists in the system, effectively allowing enumeration of valid usernames. The flaw is categorized under CWE-203 (Observable Discrepancy). Official patches addressing this issue are available in Vault Community Edition 1.20.1 and Vault Enterprise versions 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Potential Impact
The primary impact is the potential disclosure of valid usernames through timing analysis, which could aid attackers in further targeted attacks. There is no direct impact on data confidentiality, integrity, or availability. The vulnerability is rated low severity with a CVSS score of 3.7, reflecting limited impact.
Mitigation Recommendations
Apply the official patches provided by HashiCorp: upgrade to Vault Community Edition 1.20.1 or Vault Enterprise 1.20.1, 1.19.7, 1.18.12, or 1.16.23. These versions contain fixes that eliminate the timing side channel vulnerability. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- HashiCorp
- Date Reserved
- 2025-06-11T18:57:02.577Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 688d04c8ad5a09ad00cb1889
Added to database: 08/01/2025, 18:17:44 UTC
Last enriched: 09/08/2026, 13:08:03 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 241
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.