CVE-2025-6011: Timing Side-Channel in Vault’s Userpass Auth Method
A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/vaultto a version that resolves this vulnerability.Fixed in 1.20.1 - Upgrade
Upgrade
Vault Community Editionto a version that resolves this vulnerability.Fixed in 1.20.1 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.20.1 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.19.7 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.18.12 - Upgrade
Upgrade
Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.16.23
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6011?
CVE-2025-6011 is considered a moderate severity vulnerability due to its potential for user enumeration.
How do I fix CVE-2025-6011?
To mitigate CVE-2025-6011, upgrade to Vault Community Edition 1.20.1 or later, or to a patched version of Vault Enterprise.
What impact does CVE-2025-6011 have on user authentication?
CVE-2025-6011 allows attackers to potentially enumerate valid usernames through timing side channels in the userpass auth method.
Which versions of Vault are affected by CVE-2025-6011?
CVE-2025-6011 affects Vault versions prior to 1.20.1 and certain versions of Vault Enterprise between 1.20.1 and 1.16.23.
Is CVE-2025-6011 exploitable remotely?
Yes, CVE-2025-6011 can be exploited remotely by an attacker to expose valid usernames.