{"id":"CVE-2025-62513","aliases":["BIT-openbao-2025-62513","GHSA-ghfh-fmx4-26h8","GO-2025-4049"],"url":"https://o3.security/vulnerability/CVE-2025-62513","summary":"OpenBao leaks HTTPRawBody in Audit Logs","details":"### Impact\n\nOpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd).  This impacted the following subsystems:\n\n - When using the ACME functionality of PKI, this would result in short-lived ACME verification challenge codes being leaked in the audit logs.\n - When using the OIDC issuer functionality of the identity subsystem, auth and token response codes along with claims could be leaked in the audit logs.\n\nThird-party plugins may be affected.\n\n### Patches\n\nOpenBao v2.4.2 will patch this issue.\n\n### Workarounds\n\nIf users do not use the above functionality, they are not impacted. ACME verification codes are not usable after verification or challenge expiry so are of limited long-term use.","published":"2025-10-22T19:18:59.643Z","modified":"2026-08-12T03:51:27.481743475Z","cvss":null,"epss":{"score":0.00293,"percentile":0.21202,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openbao/openbao","fixedVersion":"0.0.0-20251022165510-cc2c476bac66"}],"fix":{"url":"https://github.com/openbao/openbao/commit/cc2c476bac66e1d94776c2629793daec3af625f8","label":"openbao/openbao@cc2c476"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62513.json"},{"type":"ADVISORY","url":"https://github.com/openbao/openbao/security/advisories/GHSA-ghfh-fmx4-26h8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62513"},{"type":"FIX","url":"https://github.com/openbao/openbao/commit/cc2c476bac66e1d94776c2629793daec3af625f8"},{"type":"PACKAGE","url":"https://github.com/openbao/openbao"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.481743475Z"}}