CVE-2025-4166: Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4166?
CVE-2025-4166 has a medium severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2025-4166?
To fix CVE-2025-4166, upgrade to HashiCorp Vault Community or Vault Enterprise version 1.19.4 or later.
What versions are affected by CVE-2025-4166?
CVE-2025-4166 affects HashiCorp Vault Community and Enterprise versions up to 1.19.3.
What kind of information is exposed in CVE-2025-4166?
CVE-2025-4166 may unintentionally expose sensitive information in server and audit logs.
How does CVE-2025-4166 occur?
CVE-2025-4166 occurs when users submit malformed payloads during secret creation or update operations via the Vault REST API.