« Back to list

CVE-2023-6337

Status: ModifiedHigh (7.5)—

HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash.

Fixed in Vault 1.15.4, 1.14.8, 1.13.12.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-6337",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@hashicorp.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@hashicorp.com",
      "affectedData": [
        {
          "repo": "https://github.com/hashicorp/vault",
          "vendor": "HashiCorp",
          "product": "Vault",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "1.14.8",
                  "status": "unaffected"
                },
                {
                  "at": "1.13.2",
                  "status": "unaffected"
                }
              ],
              "version": "1.12.0",
              "lessThan": "1.15.4",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Windows",
            "MacOS",
            "Linux",
            "x86",
            "ARM",
            "64 bit",
            "32 bit"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "HashiCorp",
          "product": "Vault Enterprise",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "1.14.8",
                  "status": "unaffected"
                },
                {
                  "at": "1.13.2",
                  "status": "unaffected"
                }
              ],
              "version": "1.12.0",
              "lessThan": "1.15.4",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Windows",
            "MacOS",
            "Linux",
            "x86",
            "ARM",
            "64 bit",
            "32 bit"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-08T22:15:07.713",
  "references": [
    {
      "url": "https://discuss.hashicorp.com/t/hcsec-2023-34-vault-vulnerable-to-denial-of-service-through-memory-exhaustion-when-handling-large-http-requests/60741",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@hashicorp.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240112-0006/",
      "source": "security@hashicorp.com"
    },
    {
      "url": "https://discuss.hashicorp.com/t/hcsec-2023-34-vault-vulnerable-to-denial-of-service-through-memory-exhaustion-when-handling-large-http-requests/60741",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240112-0006/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@hashicorp.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash.\n\nFixed in Vault 1.15.4, 1.14.8, 1.13.12."
    },
    {
      "lang": "es",
      "value": "HashiCorp Vault y Vault Enterprise 1.12.0 y versiones posteriores son vulnerables a una denegación de servicio debido al agotamiento de la memoria del host cuando se manejan grandes solicitudes HTTP autenticadas y no autenticadas de un cliente. Vault intentará asignar la solicitud a la memoria, lo que provocará que se agote la memoria disponible en el host, lo que puede provocar que Vault falle. Corregido en Vault 1.15.4, 1.14.8, 1.13.12."
    }
  ],
  "lastModified": "2026-06-17T06:50:33.590",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "279420C4-177B-42B2-A4D9-6E9EDA3F1D0E",
              "versionEndIncluding": "1.12.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0DB3723-28B2-48CB-9027-9A3AE4C650BD",
              "versionEndIncluding": "1.12.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCBF4C08-0C81-46C1-B9C6-843E07C78E34",
              "versionEndExcluding": "1.13.12",
              "versionStartIncluding": "1.13.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1B50279-B5C2-442A-AA6B-55DDD19ED8F5",
              "versionEndExcluding": "1.13.12",
              "versionStartIncluding": "1.13.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "885CF0FC-A707-4E8F-BCA8-45BC83FC06EE",
              "versionEndExcluding": "1.14.8",
              "versionStartIncluding": "1.14.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1BCB828-CA09-433F-96C3-4653B565DF1F",
              "versionEndExcluding": "1.14.8",
              "versionStartIncluding": "1.14.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89F657D5-0195-4A10-80B3-C12ACFFA5B0E",
              "versionEndExcluding": "1.15.4",
              "versionStartIncluding": "1.15.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB94C54C-E891-47FD-8695-DFE0652F0E30",
              "versionEndExcluding": "1.15.4",
              "versionStartIncluding": "1.15.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@hashicorp.com"
}