12 open findings · 7 with upstream fix available · 3 after VEX (9 suppressed)
not_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_present| Package | Version | Severity | CVE | Fix | Description | VEX |
|---|---|---|---|---|---|---|
| github.com/openbao/openbao | v2.5.5 | CRITICAL | GO-2025-3858 | 0.0.0-20250806194004-a14053c9679d | Privileged OpenBao Operator May Execute Code on the Underlying Host in github.com/openbao/openbao. NOTE: The source advisory for this report contains additiona | VEX |
| github.com/openbao/openbao | v2.5.5 | HIGH | GO-2025-4039 | — | OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests in github.com/openbao/openbao. NOTE: The source a | — |
| github.com/openbao/openbao | v2.5.5 | HIGH | GO-2025-3783 | — | OpenBao allows cancellation of root rekey and recovery rekey operations without authentication in github.com/openbao/openbao | — |
| github.com/openbao/openbao | v2.5.5 | HIGH | GO-2025-4156 | — | OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation in github.com/openbao/openbao. NOTE: The source advisory for this report contains a | — |
| github.com/openbao/openbao | v2.5.5 | HIGH | GO-2025-3857 | 0.0.0-20250806193240-9b0b5d4f345f | OpenBao Root Namespace Operator May Elevate Token Privileges in github.com/openbao/openbao. NOTE: The source advisory for this report contains additional versi | VEX |
| github.com/aws/aws-sdk-go | v1.55.6 | MEDIUM | GO-2022-0646 | — | A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without compu | VEX |
| github.com/openbao/openbao | v2.5.5 | MEDIUM | GO-2025-3859 | 0.0.0-20250807212521-c52795c1ef74 | OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias in github.com/openbao/openbao. NOTE: The source advisory for this report contains additional v | VEX |
| github.com/openbao/openbao | v2.5.5 | MEDIUM | GO-2025-3853 | 0.0.0-20250806193153-183891f8d535 | OpenBao TOTP Secrets Engine Code Reuse in github.com/openbao/openbao. NOTE: The source advisory for this report contains additional versions that could not be | VEX |
| github.com/openbao/openbao | v2.5.5 | MEDIUM | GO-2025-3855 | 0.0.0-20250807212521-c52795c1ef74 | OpenBao Userpass and LDAP User Lockout Bypass in github.com/openbao/openbao. NOTE: The source advisory for this report contains additional versions that could | VEX |
| github.com/openbao/openbao | v2.5.5 | MEDIUM | GO-2025-3856 | 0.0.0-20250807113757-8340a6918f6c | OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse in github.com/openbao/openbao. NOTE: The source advisory for this report contains additional ver | VEX |
| github.com/aws/aws-sdk-go | v1.55.6 | LOW | GO-2022-0635 | — | A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bu | VEX |
| github.com/openbao/openbao | v2.5.5 | LOW | GO-2025-3854 | 0.0.0-20250806193356-4d9b5d3d6486 | OpenBao has a Timing Side-Channel in the Userpass Auth Method in github.com/openbao/openbao. NOTE: The source advisory for this report contains additional vers | VEX |