{"id":"CVE-2023-5954","summary":"Vault Requests Triggering Policy Checks May Lead To Unbounded Memory Consumption","details":"HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.","aliases":["BIT-vault-2023-5954","GHSA-4qhc-v8r6-8vwm","GO-2023-2329"],"modified":"2026-08-12T03:51:09.507672178Z","published":"2023-11-09T20:13:49.346Z","related":["CGA-r754-vx36-9qrf"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"1.15.0"},{"last_affected":"1.15.0"},{"introduced":"1.15.1"},{"last_affected":"1.15.1"},{"introduced":"1.14.3"},{"last_affected":"1.14.3"},{"introduced":"1.14.4"},{"last_affected":"1.14.4"},{"introduced":"1.14.5"},{"last_affected":"1.14.5"},{"introduced":"1.13.7"},{"last_affected":"1.13.7"},{"introduced":"1.13.8"},{"last_affected":"1.13.8"},{"introduced":"1.13.9"},{"last_affected":"1.13.9"},{"introduced":"1.15.0"},{"last_affected":"1.15.0"},{"introduced":"1.15.1"},{"last_affected":"1.15.1"},{"introduced":"1.14.3"},{"last_affected":"1.14.3"},{"introduced":"1.14.4"},{"last_affected":"1.14.4"},{"introduced":"1.14.5"},{"last_affected":"1.14.5"},{"introduced":"1.13.7"},{"last_affected":"1.13.7"},{"introduced":"1.13.8"},{"last_affected":"1.13.8"},{"introduced":"1.13.9"},{"last_affected":"1.13.9"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"HashiCorp","cwe_ids":["CWE-401"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5954.json"},"references":[{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2023-33-vault-requests-triggering-policy-checks-may-lead-to-unbounded-memory-consumption/59926"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5954.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5954"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20231227-0001/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hashicorp/vault","events":[{"introduced":"895eb72029d83fcefb8a079e056e7024d8dc6020"},{"fixed":"39680359a1c5d78d05679ac94fa4f0944d442581"},{"introduced":"56debfa71653e72433345f23cd26276bc90629ce"},{"fixed":"5efc0cb9076cd49e80f6789dc978d68a9a9a5a1d"},{"introduced":"b4d07277a6c5318bb50d3b94bbd6135dccb4c601"},{"fixed":"cf1b5cafa047bc8e4a3f93444fcb4011593b92cb"}],"database_specific":{"cpe":["cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*","cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*"],"extracted_events":[{"introduced":"1.13.7"},{"fixed":"1.13.10"},{"introduced":"1.14.3"},{"fixed":"1.14.6"},{"introduced":"1.15.0"},{"fixed":"1.15.2"}],"source":"CPE_RANGE"}}],"versions":["v1.13.9","v1.14.5","v1.15.1","sdk/v0.10.2","v1.13.8","v1.14.4","v1.15.0","v1.14.3","v1.13.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5954.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}