{"id":"CVE-2025-4656","aliases":["BIT-vault-2025-4656","GHSA-fhc2-8qx8-6vj7","GO-2025-3788"],"url":"https://o3.security/vulnerability/CVE-2025-4656","summary":"Vault Vulnerable to Recovery Key Cancellation Denial of Service","details":"Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.","published":"2025-06-25T16:15:11.861Z","modified":"2026-07-15T01:49:06.976008124Z","cvss":{"score":3.1,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/hashicorp/vault","fixedVersion":"1.20.0"}],"fix":null,"references":[{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2025-11-vault-vulnerable-to-recovery-key-cancellation-denial-of-service/75570"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4656.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4656"},{"type":"PACKAGE","url":"https://github.com/hashicorp/vault"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:06.976008124Z"}}