DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-8185

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-8185

CGA ID

CGA-9qhg-hx9x-wfj4

Severity

Unknown

Summary

Hashicorp Vault vulnerable to denial of service through memory exhaustion

Description

Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint. An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself.

This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.

References

Affected packages


Safe Source for Open Source™
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Chainguard ContainersChainguard LibrariesChainguard VMs