sdk/v0.25.0
2026-03-24T08:52:20Z•0c6dde5c71d677ab04b8c870f55560739ed3a0fbf310cffbb2c46cab3228aad2
CVE-2025-63811CVE-2026-1229GHSA-f6x5-jh6r-wrfvGHSA-j5w8-q4qc-rx2xGO-2026-4394GO-2026-4503auth/awscloudflare/circldependency-upgradefilippo.io/edwards25519go.opentelemetry.io/otelgolang/x/cryptohashicorpjose2goreleasesecurityvault
What happened
Atom feed of HashiCorp Vault releases (2025–2026) highlighting multiple security fixes. Notable items: v1.21.4 upgrades cloudflare/circl to v1.6.3 to address CVE-2026-1229, upgrades filippo.io/edwards25519 to v1.1.1 (GO-2026-4503), and upgrades go.opentelemetry.io/otel/sdk to v1.40.0 (GO-2026-4394). Earlier releases include security fixes: v1.21.3 adds a certificate renewal validation for auth/cert; v1.21.2 updates golang/x/crypto to address several GHSA advisories; v1.21.1 fixes an auth/aws authentication bypass and updates jose2go to address CVE-2025-63811. Users should prioritize upgrading/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hashicorp_vault_releases
- Record identifier
- 0c6dde5c71d677ab04b8c870f55560739ed3a0fbf310cffbb2c46cab3228aad2
- Enrichment time
- 2026-03-24T08:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.