Openbao
This hub aggregates every CVE we track for Openbao, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
26
CVEs tracked
2
Critical
10
High
0
In CISA KEV
Severity distribution
HIGH10MEDIUM10LOW4CRITICAL2
Monthly trend
1
2
0
0
0
0
0
0
1
2
0
7
0
3
1
0
0
0
2
4
1
0
0
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Openbao.
- CVE-2026-46405OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens5.3
- CVE-2026-42186OpenBao's Namespace Deletion May Not Delete Data Properly7.5
- CVE-2026-40264OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation2.7
- CVE-2026-39396OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)3.1
- CVE-2026-39388OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate3.1
- CVE-2026-39946OpenBao allows SQL Injection in PostgreSQL database secrets engine4.9
- CVE-2026-33758OpenBao has Reflected XSS in its OIDC authentication error message6.1
- CVE-2026-33757OpenBao lacks user confirmation for OIDC direct callback mode9.6
- CVE-2025-64761OpenBao Privileged Operator Identity Group Root Escalation7.2
- CVE-2025-62705OpenBao and Vault Leak []byte Fields in Audit Logs4.9
- CVE-2025-62513OpenBao leaks HTTPRawBody in Audit Logs7.5
- CVE-2025-59043OpenBao vulnerable to denial of service via malicious JSON request processing7.5
- CVE-2025-55003OpenBao Login MFA Bypasses Rate Limiting and TOTP Token Reuse5.7
- CVE-2025-55001OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias6.5
- CVE-2025-55000OpenBao TOTP Secrets Engine Enables Code Reuse6.5
Product normalization is registry-driven with AI assist and human review. How it works