Skip to main content

Improper Neutralization of Whitespace

CVE-2025-6014

Severity Medium
Score 6.5/10

Summary

Vault and Vault Enterprises (Vault) TOTP Secrets Engine code validation endpoint is susceptible to Code Reuse within its validity period. This issue affects github.com/hashicorp/vault versions prior to v1.20.1. Fixed in Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-156 - Improper Neutralization of Whitespace

The software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as whitespace when they are sent to a downstream component.

Advisory Timeline

  • Published