Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HashiCorp Vault Vulnerability Let Attackers to Crash Servers

HashiCorp Vault Vulnerability Let Attackers to Crash Servers

Posted on September 2, 2025September 2, 2025 By CWS

A vital denial-of-service vulnerability in HashiCorp Vault may enable malicious actors to overwhelm servers with specifically crafted JSON payloads, resulting in extreme useful resource consumption and rendering Vault cases unresponsive. 

Tracked as CVE-2025-6203 and revealed on August 28, 2025, the flaw impacts each Vault Group and Enterprise editions from model 1.15.0 as much as a number of patched releases. 

Operators are urged to improve to Vault 1.20.3 (Group and Enterprise), 1.19.9, 1.18.14, or 1.16.25 to mitigate the problem.

Reminiscence-Primarily based DoS Vulnerability

Vault’s audit gadgets are liable for logging each request interplay earlier than finishing the request. 

A malicious consumer can submit a payload that meets the default max_request_size restrict (32 MiB by default) however leverages deeply nested JSON buildings or extreme entries to drive excessive CPU and reminiscence utilization within the audit subroutine. 

Because the JSON parser recurses by way of lengthy string values or excessive object entry counts, reminiscence consumption spikes, triggering timeouts and inflicting the Vault server to grow to be unresponsive.

HashiCorp has launched new listener configuration choices to additional harden Vault towards abusive JSON payloads. The TCP listener might now be configured with:

max_json_depth: Most nesting depth for JSON objects.

max_json_string_value_length: Most size for string values.

max_json_object_entry_count: Most variety of key/worth pairs in an object.

max_json_array_element_count: Most components in a JSON array.

Operators can discover detailed steering within the API documentation for listener parameters and the Vault improve information.

HashiCorp acknowledges Darrell Bethea, Ph.D., of Certainly for responsibly reporting this vulnerability.

Threat FactorsDetailsAffected ProductsVault Group and Vault Enterprise 1.15.0 by way of 1.20.2, 1.19.8, 1.18.13, and 1.16.24ImpactDenial of ServiceExploit PrerequisitesNetwork entry to Vault listener; potential to submit HTTP API requests with crafted JSON payloadsCVSS 3.1 Score7.5 (Excessive)

Mitigations

To remediate CVE-2025-6203, prospects ought to improve to one of many patched variations: Vault Group Version 1.20.3 or Vault Enterprise editions 1.20.3, 1.19.9, 1.18.14, or 1.16.25. 

Upgrading will allow built-in limits on JSON payload complexity, stopping the extreme recursion that triggers the Denial of Service. 

Directors are additionally inspired to evaluation their max_request_size settings and apply listener-level constraints to JSON parsing as a part of a defense-in-depth technique.

Discover this Story Fascinating! Observe us on Google Information, LinkedIn, and X to Get Extra Immediate Updates.

Cyber Security News Tags:Attackers, Crash, HashiCorp, Servers, Vault, Vulnerability

Post navigation

Previous Post: Silver Fox Exploits Microsoft-Signed WatchDog Driver to Deploy ValleyRAT Malware
Next Post: Lazarus Hackers Deploying Three RATs on Compromised Systems Possibly Using 0-Day Vulnerability

Related Posts

Lazarus Hackers Trick Users Into Believing Their Camera or Microphone is Blocked to Deliver PyLangGhost RAT Lazarus Hackers Trick Users Into Believing Their Camera or Microphone is Blocked to Deliver PyLangGhost RAT Cyber Security News
Lyrie.ai Enhances AI Security with New Protocol Lyrie.ai Enhances AI Security with New Protocol Cyber Security News
Top 3 CISO Challenges And How To Solve Them  Top 3 CISO Challenges And How To Solve Them  Cyber Security News
Threat Actors Using Fake Notepad++ and 7-zip Websites to Deploy Remote Monitoring Tools Threat Actors Using Fake Notepad++ and 7-zip Websites to Deploy Remote Monitoring Tools Cyber Security News
Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes Cyber Security News
Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mythos Excels in Vulnerability Detection, Faces Varied Challenges
  • OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices
  • Revolutionizing Data Center Security with DPUs
  • Ghostwriter Intensifies Phishing Attacks on Ukraine
  • AI Enhances Security with Realistic Attack Simulations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mythos Excels in Vulnerability Detection, Faces Varied Challenges
  • OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices
  • Revolutionizing Data Center Security with DPUs
  • Ghostwriter Intensifies Phishing Attacks on Ukraine
  • AI Enhances Security with Realistic Attack Simulations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark