Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

nvd логотип

CVE-2026-55776

8 дней назад

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter selected rsa-, ecdsa-, or ed25519. The Transit policy creation path in builtin/logical/transit/backend.go and sdk/helper/keysutil/policy.go could reach an error path that double-unlocked a mutex while handling this invalid asymmetric derived-key combination, causing a panic, no HTTP response, process exit, and denial of service. JSON and HCL key-creation requests can express the triggering combination. This issue is fixed in version 2.5.5.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-55776

8 дней назад

OpenBao is an open source identity-based secrets management system. Pr ...

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260901-80-0036

22 дня назад

Уязвимость openbao

CVSS2: 6.8
EPSS: Низкий
redos логотип

ROS-20260901-73-0025

22 дня назад

Уязвимость openbao

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-8w8f-r2xv-4q4j

3 месяца назад

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-55776

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter selected rsa-, ecdsa-, or ed25519. The Transit policy creation path in builtin/logical/transit/backend.go and sdk/helper/keysutil/policy.go could reach an error path that double-unlocked a mutex while handling this invalid asymmetric derived-key combination, causing a panic, no HTTP response, process exit, and denial of service. JSON and HCL key-creation requests can express the triggering combination. This issue is fixed in version 2.5.5.

CVSS3: 6.5
0%
Низкий
8 дней назад
debian логотип
CVE-2026-55776

OpenBao is an open source identity-based secrets management system. Pr ...

CVSS3: 6.5
0%
Низкий
8 дней назад
redos логотип
ROS-20260901-80-0036

Уязвимость openbao

CVSS2: 6.8
0%
Низкий
22 дня назад
redos логотип
ROS-20260901-73-0025

Уязвимость openbao

CVSS2: 6.8
0%
Низкий
22 дня назад
github логотип
GHSA-8w8f-r2xv-4q4j

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу