
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6203 is a denial-of-service vulnerability in HashiCorp Vault caused by insufficient resource throttling when processing complex JSON payloads. A malicious user can submit a specially-crafted payload that meets the default request size limit but causes excessive memory and CPU consumption, potentially timing out Vault's auditing subroutine and rendering the server unresponsive. The vulnerability was disclosed on August 28, 2025, and affects Vault Community Edition versions 1.15.0 through 1.20.2, and Vault Enterprise versions across multiple branches. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, HashiCorp Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling): Vault does not impose adequate restrictions on the computational complexity of JSON payloads, even when those payloads fall within the configured request size limit. An attacker can craft a deeply nested or otherwise complex JSON structure that triggers disproportionate memory and CPU usage during processing, particularly within Vault's auditing subroutine. The attack requires no authentication, no user interaction, and is exploitable remotely over the network, making it accessible to any party with network access to the Vault API endpoint. A related incomplete fix was later disclosed under HCSEC-2025-32, indicating the initial patch did not fully resolve the underlying issue (HashiCorp Advisory, HashiCorp Follow-up, GitHub Advisory).
Successful exploitation results in complete unavailability of the Vault server, disrupting all secret management, authentication, and encryption-as-a-service operations dependent on it. Because Vault is commonly used as a central secrets broker in enterprise and cloud-native environments, an outage can cascade to dependent applications and services that rely on dynamic credentials or token issuance. There is no confidentiality or integrity impact — the vulnerability is purely an availability concern, but the criticality of Vault's role in infrastructure makes even temporary unavailability highly disruptive (HashiCorp Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.04–0.10%, reflecting a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. However, the unauthenticated, network-accessible nature of the attack vector lowers the barrier for exploitation significantly.
HashiCorp has released patches addressing this vulnerability: Vault Community Edition 1.20.3, and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25. Operators should upgrade to these versions immediately. As interim mitigations, implementing network-level controls to restrict access to the Vault API to trusted sources, and monitoring Vault server resource utilization for anomalies, are recommended. Note that a follow-up advisory (HCSEC-2025-32) was issued indicating the initial fix was incomplete, so operators should ensure they are running the latest available patched release (HashiCorp Advisory, HashiCorp Follow-up, GitHub Advisory).
The vulnerability received coverage from multiple security news outlets including GBHackers, SecurityOnline, CyberSecurityNews, and CyberPress, all highlighting the unauthenticated nature of the attack and its potential to crash Vault servers. The Hacker News weekly recap included CVE-2025-6203 among notable vulnerabilities for the week of August 25, 2025. BlackKite's Focus Friday TPRM analysis flagged it as a relevant third-party risk management concern. Social media activity on Mastodon and X (Twitter) noted the disclosure shortly after publication. The CISA vulnerability bulletin for the week of August 25, 2025 also referenced the vulnerability (GBHackers, HashiCorp Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."