HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash.Fixed in Vault 1.15.4, 1.14.8, 1.13.12.
{ "cpes": [ "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*", "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*" ], "severity": "High" }