Known vulnerabilities in openbao
Vendor:
Fedoraproject
Software:
openbao
Software CPE:
cpe:2.3:o:fedoraproject:openbao:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
21
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
2.6.2-1.el10_3
2.6.2-1.el8
2.6.2-1.fc44
2.6.2-1.fc43
2.6.2-1.el10_2
2.6.2-1.el9
2.5.5-1.el10_2
2.5.5-1.fc43
2.5.5-1.el10_3
2.5.5-1.el9
2.5.5-1.fc44
2.5.5-1.el8
2.5.4-1.el8
2.5.4-1.el9
2.5.4-1.fc42
2.5.4-1.fc43
2.5.4-1.el10_2
2.5.4-1.el10_3
2.5.3-1.el9
2.5.3-1.el10_2
2.5.3-1.fc42
2.5.3-1.fc44
2.5.3-1.el10_1
2.5.3-1.fc43
2.5.3-1.el10_3
2.5.3-1.el8
2.5.2-1.fc43
2.5.2-1.el10_1
2.5.2-1.fc42
2.5.2-1.el10_3
2.5.2-1.el9
2.5.2-1.fc44
2.5.2-1.el10_2
2.5.2-1.el8
2.5.1-1.el8
2.5.0-1.el8
2.4.3-2.fc42
2.4.3-2.fc41
2.4.3-2.fc43
2.4.3-1.fc42
2.4.3-1.fc41
2.4.3-1.el10_2
2.4.3-1.el10_0
2.4.3-1.fc43
2.4.3-1.el9
2.4.3-1.el10_1
2.4.3-1.el8
Vulnerabilities (21)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU144303 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CVE-2026-55770 |
CWE-90 | Low | 2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44 | 19.08.2026 |
SB2026081962 SB2026081965 SB2026081966 and 4 more |
||
| #VU144302 - Incorrect Authorization CVE-2026-55774 |
CWE-863 | Low | 2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44 | 19.08.2026 |
SB2026081962 SB2026081965 SB2026081966 and 4 more |
||
| #VU144301 - Reachable Assertion CVE-2026-55776 |
CWE-617 | Low | 2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44 | 19.08.2026 |
SB2026081962 SB2026081965 SB2026081966 and 4 more |
||
| #VU144300 - Improper Authorization CVE-2026-55775 |
CWE-285 | Low | 2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44 | 19.08.2026 |
SB2026081962 SB2026081965 SB2026081966 and 4 more |
||
| #VU132078 - Incorrect Authorization CVE-2026-45808 |
CWE-863 | Low | 2.5.4-1.el8, 2.5.4-1.el9, 2.5.4-1.el10_2, 2.5.4-1.el10_3, 2.5.4-1.fc42, 2.5.4-1.fc43 | 21.05.2026 |
SB2026052132 SB2026052133 SB2026052134 and 4 more |
||
| #VU132077 - Improper Access Control CVE-2026-46405 |
CWE-284 | Medium | 2.5.4-1.el8, 2.5.4-1.el9, 2.5.4-1.el10_2, 2.5.4-1.el10_3, 2.5.4-1.fc42, 2.5.4-1.fc43 | 21.05.2026 |
SB2026052132 SB2026052133 SB2026052134 and 4 more |
||
| #VU132076 - Information Exposure Through Log Files CVE-2026-46358 |
CWE-532 | Medium | 2.5.4-1.el8, 2.5.4-1.el9, 2.5.4-1.el10_2, 2.5.4-1.el10_3, 2.5.4-1.fc42, 2.5.4-1.fc43 | 21.05.2026 |
SB2026052132 SB2026052133 SB2026052134 and 4 more |
||
| #VU126701 - Allocation of Resources Without Limits or Throttling CVE-2026-39396 |
CWE-770 | Low | 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44 | 21.04.2026 |
SB2026042149 SB2026042172 SB2026042173 and 6 more |
||
| #VU126699 - Improper Authentication CVE-2026-39388 |
CWE-287 | Low | 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44 | 21.04.2026 |
SB2026042149 SB2026042172 SB2026042173 and 6 more |
||
| #VU126698 - Improper Access Control CVE-2026-40264 |
CWE-284 | Low | 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44 | 21.04.2026 |
SB2026042149 SB2026042172 SB2026042173 and 6 more |
||
| #VU126697 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-33758 |
CWE-79 | Medium | 2.5.2-1.el8, 2.5.2-1.el9, 2.5.2-1.el10_1, 2.5.2-1.el10_2, 2.5.2-1.el10_3, 2.5.2-1.fc42, 2.5.2-1.fc43, 2.5.2-1.fc44 | 21.04.2026 |
SB2026042148 SB2026042150 SB2026042151 and 6 more |
||
| #VU126696 - Missing Authentication for Critical Function CVE-2026-33757 |
CWE-306 | High | 2.5.2-1.el8, 2.5.2-1.el9, 2.5.2-1.el10_1, 2.5.2-1.el10_2, 2.5.2-1.el10_3, 2.5.2-1.fc42, 2.5.2-1.fc43, 2.5.2-1.fc44 | 21.04.2026 |
SB2026042148 SB2026042150 SB2026042151 and 6 more |
||
| #VU125945 - Improper input validation CVE-2026-34986 |
CWE-20 | Medium | 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44 | 14.04.2026 |
SB2026041463 SB2026041464 SB2026041465 and 74 more |
||
| #VU118190 - Resource exhaustion CVE-2025-58183 |
CWE-400 | Medium | 2.4.3-2.fc41, 2.4.3-2.fc42, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 | 07.11.2025 |
SB2025110705 SB2025110725 SB2025110726 and 177 more |
||
| #VU118189 - Improper input validation CVE-2025-58188 |
CWE-20 | Medium | 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 | 07.11.2025 |
SB2025110705 SB2025110716 SB2025110717 and 113 more |
||
| #VU118187 - Resource exhaustion CVE-2025-58185 |
CWE-400 | Medium | 2.4.3-2.fc41, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 | 07.11.2025 |
SB2025110705 SB2025110716 SB2025110717 and 115 more |
||
| #VU118184 - Resource exhaustion CVE-2025-61723 |
CWE-400 | Medium | 2.4.3-2.fc41, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 | 07.11.2025 |
SB2025110705 SB2025110716 SB2025110717 and 121 more |
||
| #VU118183 - Improper Encoding or Escaping of Output CVE-2025-58189 |
CWE-116 | Low | 2.4.3-2.fc41, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 | 07.11.2025 |
SB2025110705 SB2025110711 SB2025110712 and 123 more |
||
| #VU118179 - Resource exhaustion CVE-2025-61725 |
CWE-400 | Medium | 2.4.3-2.fc41, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 | 07.11.2025 |
SB2025110705 SB2025110714 SB2025110715 and 76 more |
||
| #VU117702 - Information Exposure Through Log Files CVE-2025-62513 |
CWE-532 | Low | 2.4.3-1.el8, 2.4.3-1.el9, 2.4.3-1.el10_0, 2.4.3-1.el10_1, 2.4.3-1.el10_2, 2.4.3-1.fc41, 2.4.3-1.fc42, 2.4.3-1.fc43 | 28.10.2025 |
SB2025102837 SB2025102840 SB2025102841 and 6 more |
Showing elements 1 - 20 out of 21