PT-2025-42622 · Openbao+1 · Openbao+1

Published

2025-10-17

·

Updated

2026-02-09

·

CVE-2025-59043

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.4.1
Description OpenBao is an open source identity-based secrets management system. Versions prior to 2.4.1 are susceptible to a denial of service condition. Specifically, crafted JSON payloads can cause excessive memory usage during decoding, potentially exceeding the max request size configuration parameter. This can lead to an out-of-memory crash, even for unauthenticated attackers. Additionally, requests containing a large number of strings can cause high CPU consumption within the audit subsystem. The issue stems from a significant difference between the memory used by serialized and deserialized JSON objects, with exploitation factors reaching approximately 35.
Recommendations Update to OpenBao version 2.4.1 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59043
GHSA-G46H-2RQ9-GW5M
GO-2025-4039
OPENSUSE-SU-2025:15710-1

Affected Products

Openbao
Red Os