Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.
Details
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.
Statement
Subscribe to updates
Product 1
Loading products...
No products found
Loading...
No matches
Unsubscribe
Enter your email and we'll send you a link to manage your subscription preferences.
Check your inbox
If this email is subscribed, we've sent a link to manage your preferences.
Contact us
Message Delivered!
Thanks for reaching out!
The TuxCare team has received your message and will get back to you shortly.