Known vulnerabilities in openbao

Software: openbao
Software CPE: cpe:2.3:o:fedoraproject:openbao:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 21
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openbao openbao is affected by 21 known vulnerabilities: 1 high, 9 medium, 11 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144303 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE-2026-55770
CWE-90 Low
No
No
2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44 19.08.2026 SB2026081962
SB2026081965
SB2026081966
and 4 more
#VU144302 - Incorrect Authorization
CVE-2026-55774
CWE-863 Low
No
No
2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44 19.08.2026 SB2026081962
SB2026081965
SB2026081966
and 4 more
#VU144301 - Reachable Assertion
CVE-2026-55776
CWE-617 Low
No
No
2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44 19.08.2026 SB2026081962
SB2026081965
SB2026081966
and 4 more
#VU144300 - Improper Authorization
CVE-2026-55775
CWE-285 Low
No
No
2.5.5-1.el8, 2.5.5-1.el9, 2.5.5-1.el10_2, 2.5.5-1.el10_3, 2.5.5-1.fc43, 2.5.5-1.fc44 19.08.2026 SB2026081962
SB2026081965
SB2026081966
and 4 more
#VU132078 - Incorrect Authorization
CVE-2026-45808
CWE-863 Low
No
No
2.5.4-1.el8, 2.5.4-1.el9, 2.5.4-1.el10_2, 2.5.4-1.el10_3, 2.5.4-1.fc42, 2.5.4-1.fc43 21.05.2026 SB2026052132
SB2026052133
SB2026052134
and 4 more
#VU132077 - Improper Access Control
CVE-2026-46405
CWE-284 Medium
No
No
2.5.4-1.el8, 2.5.4-1.el9, 2.5.4-1.el10_2, 2.5.4-1.el10_3, 2.5.4-1.fc42, 2.5.4-1.fc43 21.05.2026 SB2026052132
SB2026052133
SB2026052134
and 4 more
#VU132076 - Information Exposure Through Log Files
CVE-2026-46358
CWE-532 Medium
No
No
2.5.4-1.el8, 2.5.4-1.el9, 2.5.4-1.el10_2, 2.5.4-1.el10_3, 2.5.4-1.fc42, 2.5.4-1.fc43 21.05.2026 SB2026052132
SB2026052133
SB2026052134
and 4 more
#VU126701 - Allocation of Resources Without Limits or Throttling
CVE-2026-39396
CWE-770 Low
No
No
2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44 21.04.2026 SB2026042149
SB2026042172
SB2026042173
and 6 more
#VU126699 - Improper Authentication
CVE-2026-39388
CWE-287 Low
No
No
2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44 21.04.2026 SB2026042149
SB2026042172
SB2026042173
and 6 more
#VU126698 - Improper Access Control
CVE-2026-40264
CWE-284 Low
No
No
2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44 21.04.2026 SB2026042149
SB2026042172
SB2026042173
and 6 more
#VU126697 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-33758
CWE-79 Medium
No
No
2.5.2-1.el8, 2.5.2-1.el9, 2.5.2-1.el10_1, 2.5.2-1.el10_2, 2.5.2-1.el10_3, 2.5.2-1.fc42, 2.5.2-1.fc43, 2.5.2-1.fc44 21.04.2026 SB2026042148
SB2026042150
SB2026042151
and 6 more
#VU126696 - Missing Authentication for Critical Function
CVE-2026-33757
CWE-306 High
No
No
2.5.2-1.el8, 2.5.2-1.el9, 2.5.2-1.el10_1, 2.5.2-1.el10_2, 2.5.2-1.el10_3, 2.5.2-1.fc42, 2.5.2-1.fc43, 2.5.2-1.fc44 21.04.2026 SB2026042148
SB2026042150
SB2026042151
and 6 more
#VU125945 - Improper input validation
CVE-2026-34986
CWE-20 Medium
No
No
2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44 14.04.2026 SB2026041463
SB2026041464
SB2026041465
and 74 more
#VU118190 - Resource exhaustion
CVE-2025-58183
CWE-400 Medium
No
No
2.4.3-2.fc41, 2.4.3-2.fc42, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 07.11.2025 SB2025110705
SB2025110725
SB2025110726
and 177 more
#VU118189 - Improper input validation
CVE-2025-58188
CWE-20 Medium
No
No
2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 113 more
#VU118187 - Resource exhaustion
CVE-2025-58185
CWE-400 Medium
No
No
2.4.3-2.fc41, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 115 more
#VU118184 - Resource exhaustion
CVE-2025-61723
CWE-400 Medium
No
No
2.4.3-2.fc41, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 121 more
#VU118183 - Improper Encoding or Escaping of Output
CVE-2025-58189
CWE-116 Low
No
No
2.4.3-2.fc41, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 07.11.2025 SB2025110705
SB2025110711
SB2025110712
and 123 more
#VU118179 - Resource exhaustion
CVE-2025-61725
CWE-400 Medium
No
No
2.4.3-2.fc41, 2.4.3-2.fc43, 2.5.0-1.el8, 2.5.1-1.el8 07.11.2025 SB2025110705
SB2025110714
SB2025110715
and 76 more
#VU117702 - Information Exposure Through Log Files
CVE-2025-62513
CWE-532 Low
No
No
2.4.3-1.el8, 2.4.3-1.el9, 2.4.3-1.el10_0, 2.4.3-1.el10_1, 2.4.3-1.el10_2, 2.4.3-1.fc41, 2.4.3-1.fc42, 2.4.3-1.fc43 28.10.2025 SB2025102837
SB2025102840
SB2025102841
and 6 more


Showing elements 1 - 20 out of 21