v2.0.1
2026-05-22T08:52:20Z•041d6bfb9171becf2be504ca7e3499bab1f8ca86af337e28e41be308944fd57d
CVE-2026-1229CVE-2026-34986CVE-2026-39883GHSA-j88v-2chj-qfwxGHSA-wf45-q9ch-q8ghGO-2026-4503GO-2026-4918audit-validationauth-bypasscontainerdependency-updatehashicorp-vaultntlmpostgresql-pgxreleasesecurity-update
What happened
HashiCorp Vault releases v2.0.0 and v2.0.1 include multiple security fixes and dependency updates. Notable items: updates to third‑party libraries to remediate vulnerabilities (CVE-2026-1229 in cloudflare/circl; CVE-2026-39883 in OpenTelemetry; CVE-2026-34986 in go-jose), fixes for GO-2026-4918 and GO-2026-4503 Go issues, removal/upgrade of pgx dependencies to address GHSA-j88v-2chj-qfwx, fixes for GHSA-wf45-q9ch-q8gh (Apache Thrift), update to Azure go-ntlmssp, validation to prevent empty sys/audit path/file_path, and a fix for an auth/aws caching issue that could allow authentication bypass.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hashicorp_vault_releases
- Record identifier
- 041d6bfb9171becf2be504ca7e3499bab1f8ca86af337e28e41be308944fd57d
- Enrichment time
- 2026-05-22T08:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.