/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-9qhg-hx9x-wfj4

Published

Last updated

https://images.chainguard.dev/security/CGA-9qhg-hx9x-wfj4
Package

vault-1.13

RepositoryWolfi
Latest Update
Under investigation
Aliases
  • CVE-2024-8185
  • GHSA-g233-2p4r-3q7v

Severity

Unknown

Summary

Hashicorp Vault vulnerable to denial of service through memory exhaustion

Description

Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint. An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself.

This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.

References

Updates


Safe Source for Open Source™
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs