PT-2025-42622 · Openbao+1 · Openbao+1
Published
2025-10-17
·
Updated
2026-02-09
·
CVE-2025-59043
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenBao versions prior to 2.4.1
Description
OpenBao is an open source identity-based secrets management system. Versions prior to 2.4.1 are susceptible to a denial of service condition. Specifically, crafted JSON payloads can cause excessive memory usage during decoding, potentially exceeding the
max request size configuration parameter. This can lead to an out-of-memory crash, even for unauthenticated attackers. Additionally, requests containing a large number of strings can cause high CPU consumption within the audit subsystem. The issue stems from a significant difference between the memory used by serialized and deserialized JSON objects, with exploitation factors reaching approximately 35.Recommendations
Update to OpenBao version 2.4.1 or later.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbao
Red Os