HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
High severity
GitHub Reviewed
Published
Apr 17, 2026
to the GitHub Advisory Database
•
Updated Apr 18, 2026
Package
Affected versions
>= 0.11.2, <= 1.21.4
Patched versions
None
Description
Published by the National Vulnerability Database
Apr 17, 2026
Published to the GitHub Advisory Database
Apr 17, 2026
Reviewed
Apr 18, 2026
Last updated
Apr 18, 2026
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
References