Security

Vault: what changed

In the last 90 days, 21 summarized changes: 1 end-of-life notices, 20 releases. Stackdiff reads Vault's own feeds (developer.hashicorp.com) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

2.0End of lifehigh
HashiCorp Vault 2.0 reached end of life on 2026-08-31
ActionPlan the upgrade before the date.

End of life

Support windows from endoflife.date. An entry appears the day a date enters the 120-day horizon.

CycleWhatPublished
2.0HashiCorp Vault 2.0 reached end of life on 2026-08-31

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

1.19.21+ent.hsm.fips1403Release
Vault 1.19.21+ent.hsm.fips1403
1.19.21+ent.fips1403Release
Vault 1.19.21+ent.fips1403
2.1.0+ent.hsm.fips1403Release
Vault 2.1.0+ent.hsm.fips1403
1.19.21+ent.hsmRelease
Vault 1.19.21+ent.hsm
2.1.0+ent.fips1403Release
Vault 2.1.0+ent.fips1403
1.19.21+entRelease
Vault 1.19.21+ent
2.1.0+ent.hsmRelease
Vault 2.1.0+ent.hsm
2.1.0+entRelease
Vault 2.1.0+ent
1.20.15+ent.hsm.fips1403Release
Vault 1.20.15+ent.hsm.fips1403
1.21.10+ent.hsm.fips1403Release
Vault 1.21.10+ent.hsm.fips1403
1.20.15+ent.fips1403Release
Vault 1.20.15+ent.fips1403
1.21.10+ent.fips1403Release
Vault 1.21.10+ent.fips1403
1.20.15+ent.hsmRelease
Vault 1.20.15+ent.hsm
1.21.10+ent.hsmRelease
Vault 1.21.10+ent.hsm
1.20.15+entRelease
Vault 1.20.15+ent
1.21.10+entRelease
Vault 1.21.10+ent
2.1.0Release
Vault 2.1.0
2.0End of lifehigh
HashiCorp Vault 2.0 reached end of life on 2026-08-31
ActionPlan the upgrade before the date.
1.19.20+ent.hsm.fips1403Release
Vault 1.19.20+ent.hsm.fips1403
1.21.9+ent.hsm.fips1403Release
Vault 1.21.9+ent.hsm.fips1403
1.19.20+ent.fips1403Release
Vault 1.19.20+ent.fips1403
Securityhigh
GHSA-88v5-9hxc-f85r: HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
Securityhigh
GHSA-m2w4-8ggf-rj47: HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service
Securityhigh
GHSA-72gw-fmmr-c4r4: HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
Securitymedium
GHSA-8r5m-3f66-qpr3: HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
1.21.0Securityhigh
GHSA-vp5w-xcfc-73wf: Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON
1.21.0Securityhigh
GHSA-9g4h-h484-3578: HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass
1.20.3Securityhigh
GHSA-8f82-53h8-2p34: HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads
1.20.2Securitymedium
GHSA-7rx2-769v-hrwf: HashiCorp Vault ldap auth method may not have correctly enforced MFA
1.20.1Securitymedium
GHSA-6c5r-4wfc-3mcx: Hashicorp Vault has Incorrect Validation for Non-CA Certificates

Where Stackdiff reads Vault

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get Vault changes in your Monday brief

Add Vault and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other security tools