HashiCorp Vault vulnerabilities: known CVEs & security history
HashiCorp · Secrets management · 72 tracked CVEs · 0 actively exploited · updated June 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all HashiCorp Vault release lines — 72 in total. A CVE here doesn't mean your version is affected — check HashiCorp Vault's current status and the safe version to run.
Known HashiCorp Vault CVEs
Actively-exploited and most-severe first. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2020-35192 | critical | 9.8 | 3% | 2020 |
| CVE-2020-12757 | critical | 9.8 | 2% | 2020 |
| CVE-2025-6000 | critical | 9.1 | 1% | 2025 |
| CVE-2022-40186 | critical | 9.1 | 1% | 2022 |
| CVE-2022-36129 | critical | 9.1 | 1% | 2022 |
| CVE-2020-10661 | critical | 9.1 | 1% | 2020 |
| CVE-2020-16251 | high | 8.2 | 3% | 2020 |
| CVE-2020-16250 | high | 8.2 | 2% | 2020 |
| CVE-2026-3605 | high | 8.1 | 0% | 2026 |
| CVE-2025-11621 | high | 8.1 | 0% | 2025 |
| CVE-2024-2048 | high | 8.1 | 0% | 2024 |
| CVE-2021-42135 | high | 8.1 | 1% | 2021 |
| CVE-2018-19786 | high | 8.1 | 1% | 2018 |
| CVE-2023-5077 | high | 7.6 | 0% | 2023 |
| CVE-2026-5807 | high | 7.5 | 0% | 2026 |
| CVE-2026-4525 | high | 7.5 | 0% | 2026 |
| CVE-2025-12044 | high | 7.5 | 1% | 2025 |
| CVE-2025-6203 | high | 7.5 | 1% | 2025 |
| CVE-2024-8185 | high | 7.5 | 0% | 2024 |
| CVE-2024-7594 | high | 7.5 | 0% | 2024 |
| CVE-2024-6468 | high | 7.5 | 0% | 2024 |
| CVE-2023-6337 | high | 7.5 | 1% | 2023 |
| CVE-2021-29653 | high | 7.5 | 1% | 2021 |
| CVE-2021-27400 | high | 7.5 | 1% | 2021 |
| CVE-2021-3282 | high | 7.5 | 1% | 2021 |
| CVE-2020-13223 | high | 7.5 | 1% | 2020 |
| CVE-2020-7220 | high | 7.5 | 1% | 2020 |
| CVE-2021-32923 | high | 7.4 | 1% | 2021 |
| CVE-2025-5999 | high | 7.2 | 0% | 2025 |
| CVE-2024-9180 | high | 7.2 | 1% | 2024 |
| CVE-2025-6037 | medium | 6.8 | 0% | 2025 |
| CVE-2023-4680 | medium | 6.8 | 0% | 2023 |
| CVE-2020-25816 | medium | 6.8 | 1% | 2020 |
| CVE-2025-3879 | medium | 6.6 | 0% | 2025 |
| CVE-2025-6013 | medium | 6.5 | 0% | 2025 |
| CVE-2025-6014 | medium | 6.5 | 0% | 2025 |
| CVE-2023-0665 | medium | 6.5 | 0% | 2023 |
| CVE-2023-0620 | medium | 6.5 | 0% | 2023 |
| CVE-2022-25244 | medium | 6.5 | 1% | 2022 |
| CVE-2022-25243 | medium | 6.5 | 1% | 2022 |
| CVE-2021-43998 | medium | 6.5 | 1% | 2021 |
| CVE-2024-2660 | medium | 6.4 | 0% | 2024 |
| CVE-2024-8365 | medium | 6.2 | 0% | 2024 |
| CVE-2023-5954 | medium | 5.9 | 1% | 2023 |
| CVE-2025-6015 | medium | 5.7 | 0% | 2025 |
| CVE-2024-2877 | medium | 5.5 | 0% | 2024 |
| CVE-2026-5052 | medium | 5.3 | 0% | 2026 |
| CVE-2025-6004 | medium | 5.3 | 0% | 2025 |
| CVE-2023-3462 | medium | 5.3 | 1% | 2023 |
| CVE-2022-41316 | medium | 5.3 | 0% | 2022 |
| CVE-2022-30689 | medium | 5.3 | 1% | 2022 |
| CVE-2021-27668 | medium | 5.3 | 1% | 2021 |
| CVE-2021-38554 | medium | 5.3 | 1% | 2021 |
| CVE-2021-3024 | medium | 5.3 | 1% | 2021 |
| CVE-2020-25594 | medium | 5.3 | 1% | 2021 |
| CVE-2020-35453 | medium | 5.3 | 1% | 2020 |
| CVE-2020-35177 | medium | 5.3 | 1% | 2020 |
| CVE-2020-10660 | medium | 5.3 | 1% | 2020 |
| CVE-2023-25000 | medium | 5 | 0% | 2023 |
| CVE-2023-3774 | medium | 4.9 | 1% | 2023 |
| CVE-2021-45042 | medium | 4.9 | 1% | 2021 |
| CVE-2025-4166 | medium | 4.5 | 0% | 2025 |
| CVE-2024-0831 | medium | 4.5 | 1% | 2024 |
| CVE-2023-24999 | medium | 4.4 | 1% | 2023 |
| CVE-2021-38553 | medium | 4.4 | 0% | 2021 |
| CVE-2023-2121 | medium | 4.3 | 0% | 2023 |
| CVE-2023-3775 | medium | 4.2 | 0% | 2023 |
| CVE-2025-6011 | low | 3.7 | 0% | 2025 |
| CVE-2025-4656 | low | 3.1 | 0% | 2025 |
| CVE-2021-41802 | low | 2.9 | 1% | 2021 |
| CVE-2024-5798 | low | 2.6 | 0% | 2024 |
| CVE-2023-2197 | low | 2.5 | 0% | 2023 |
Is my HashiCorp Vault version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your HashiCorp Vault version → · Monitor HashiCorp Vault for new CVEs →
HashiCorp Vault vulnerabilities — frequently asked
How many known vulnerabilities does HashiCorp Vault have?
IsItPatched tracks 72 CVEs for HashiCorp Vault. 6 are critical-severity and 24 high-severity. These span every release line — what matters is whether the version you run is affected.
Does HashiCorp Vault have any actively-exploited vulnerabilities?
None of HashiCorp Vault's tracked CVEs are currently in CISA's KEV catalog — but new ones can be added at any time, so keep your version current.
What is the most severe HashiCorp Vault vulnerability?
Among tracked issues, CVE-2020-35192 (CRITICAL, CVSS 9.8) ranks highest — a Missing authentication weakness.
Is HashiCorp Vault safe to use?
It depends on the version. The latest supported HashiCorp Vault release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: HashiCorp Vault security status · HashiCorp Vault end-of-life · actively-exploited CVEs. Always verify against HashiCorp's advisories — see our disclaimer.