GHSA-72gw-fmmr-c4r4

Suggest an improvement
Source
https://github.com/advisories/GHSA-72gw-fmmr-c4r4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-72gw-fmmr-c4r4/GHSA-72gw-fmmr-c4r4.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-72gw-fmmr-c4r4
Aliases
Downstream
CGA (25)
MINI (2)
Published
2026-04-17T06:31:07Z
Modified
2026-07-21T14:00:28Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
Details

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Database specific
{
    "cwe_ids": [
        "CWE-201"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-18T00:53:01Z",
    "nvd_published_at": "2026-04-17T04:16:09Z",
    "severity": "HIGH"
}
References

Affected packages

Go / github.com/hashicorp/vault

Package

Name
github.com/hashicorp/vault
View open source insights on deps.dev
Purl
pkg:golang/github.com/hashicorp/vault

Affected ranges

Type
SEMVER
Events
Introduced
0.11.2
Last Affected
1.21.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-72gw-fmmr-c4r4/GHSA-72gw-fmmr-c4r4.json"