CVE-2025-12044: Vault Vulnerable to Denial of Service Due to Rate Limit Regression
Vault and Vault Enterprise ("Vault") are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [+HCSEC-2025-24+|https://discuss.hashicorp.com/t/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads/76393] which allowed for processing JSON payloads before applying rate limits. This vulnerability, CVE-2025-12044, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.16.27, 1.19.11, 1.20.5, and 1.21.0.
Other sources
Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [+HCSEC-2025-24+|https://discuss.hashicorp.com/t/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads/76393] which allowed for processing JSON payloads before applying rate limits. This vulnerability, CVE-2025-12044, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.16.27, 1.19.11, 1.20.5, and 1.21.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12044?
CVE-2025-12044 is classified as a medium severity vulnerability affecting Vault and Vault Enterprise.
How do I fix CVE-2025-12044?
To remediate CVE-2025-12044, update to Vault version 1.21.0 or later for both Vault and Vault Enterprise.
What types of attacks are possible with CVE-2025-12044?
CVE-2025-12044 allows for unauthenticated denial of service attacks when processing complex JSON payloads.
Which versions of HashiCorp Vault are affected by CVE-2025-12044?
CVE-2025-12044 affects HashiCorp Vault versions prior to 1.21.0 and specific versions of Vault Enterprise within an inclusive range.
Who is at risk from CVE-2025-12044?
Organizations using affected versions of HashiCorp Vault or Vault Enterprise are at risk from CVE-2025-12044.