PT-2025-26865 · Openbao · Openbao

Cipherboy

·

Published

2025-06-25

·

Updated

2025-08-12

·

CVE-2025-52893

CVSS v3.1

4.5

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OpenBao versions prior to 2.3.0
Description: The issue concerns the potential leak of sensitive information in logs when processing malformed data. This problem has been identified in OpenBao, a software solution designed to manage, store, and distribute sensitive data, including secrets, certificates, and keys. There are no known real-world incidents or estimated numbers of affected devices mentioned.
Recommendations: For versions prior to 2.3.0, update to version 2.3.0 or later to resolve the issue. As a temporary workaround, ensure properly formatted requests from all clients to minimize the risk of sensitive information leakage.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-52893
GHSA-8F5R-8CMQ-7FMQ
GO-2025-3780
OPENSUSE-SU-2025:15254-1
OPENSUSE-SU-2025:15405-1

Affected Products

Openbao