sdk/v0.24.0
2026-03-20T08:52:16Z•3b2d27b00e61fd2cba175270d14624a0ba98e9e77e1eff3dd0d6bd0d15cbe217
CVE-2025-63811CVE-2026-1229auth/awsauth/certcloudflare/circldependency-upgradeedwards25519golanghashicorpopentelemetryreleasesecurityvault
What happened
HashiCorp Vault v1.21.x releases (notably v1.21.4) include multiple security-related dependency upgrades and fixes. v1.21.4 upgrades cloudflare/circl to v1.6.3 to address CVE-2026-1229 (GHSA-q9hv-hpm4-hj6x), upgrades filippo.io/edwards25519 to v1.1.1 (GO-2026-4503), and updates go.opentelemetry.io/otel/sdk to v1.40.0 (GO-2026-4394). Earlier v1.21.3 fixed an auth/cert renewal validation to ensure renewed certificates match the session certificate. v1.21.2 updated golang/x/crypto to v0.45.0 to address GHSA-f6x5-jh6r-wrfv, GHSA-j5w8-q4qc-rx2x and related GO-2025 issues. v1.21.1 fixed an auth/aws‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hashicorp_vault_releases
- Record identifier
- 3b2d27b00e61fd2cba175270d14624a0ba98e9e77e1eff3dd0d6bd0d15cbe217
- Enrichment time
- 2026-03-20T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.