Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
Fixed in: 2.0.0, 1.21.5, 1.20.10, 1.19.16
details
- Finding IDs
- F-VAULT-AUTHZ-BEARER-TOKEN-LEAK-001
- CVE
- CVE-2026-4525
- Status
- patched
- Fixed in
- 2.0.0, 1.21.5, 1.20.10, 1.19.16
- Recorded credit
- identified and reported by Oleh Konko of 1seal (HCSEC-2026-07)
- Note
- Vault token leaked to auth plugin backends via Authorization: Bearer passthrough header
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- CVE registry state
- PUBLISHED
- CVE state checked
F-VAULT-AUTHZ-BEARER-TOKEN-LEAK-001: Secret handling. An authorization bearer token is exposed through backend header forwarding. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-VAULT-AUTHZ-BEARER-TOKEN-LEAK-001
Security area (1seal assessment): Confidentiality. An authorization bearer token is exposed through backend header forwarding. Reviewed 24 Sep 2026.