Insertion of Sensitive Information Into Sent Data Affecting github.com/hashicorp/vault/vault package, versions >=0.11.2 <2.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.59% (46th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMHASHICORPVAULTVAULT-16110813
  • published20 Apr 2026
  • disclosed17 Apr 2026
  • creditUnknown

Introduced: 17 Apr 2026

CVE-2026-4525  (opens in a new tab)
CWE-201  (opens in a new tab)

How to fix?

Upgrade github.com/hashicorp/vault/vault to version 2.0.0 or higher.

Overview

github.com/hashicorp/vault/vault is a tool for securely accessing secrets.

Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data through the CheckToken request handling in vault/request_handling.go. An attacker can cause Vault to forward a request containing a Vault bearer token in the Authorization header to a plugin backend by sending a request to a mount or auth method configured to passthrough that header. The backend receives the Vault token alongside any other authorization values, exposing credentials to the plugin and allowing the token to be reused or logged by code that should not see it.

Notes

  • The vulnerable path is gated by mounts or auth methods that explicitly list Authorization in passthrough_request_headers; deployments that do not opt into that header passthrough are not exposed by this issue.
  • The leak is limited to requests that authenticate with a Vault bearer token in the Authorization header.

CVSS Base Scores

version 4.0
version 3.1