Improper Neutralization of Whitespace
CVE-2025-6014
Summary
Vault and Vault Enterprises (Vault) TOTP Secrets Engine code validation endpoint is susceptible to Code Reuse within its validity period. This issue affects github.com/hashicorp/vault versions prior to v1.20.1. Fixed in Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- HIGH
- NONE
CWE-156 - Improper Neutralization of Whitespace
The software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as whitespace when they are sent to a downstream component.
References
Advisory Timeline
- Published