sdk/v0.24.0

2026-03-20T08:52:16Z3b2d27b00e61fd2cba175270d14624a0ba98e9e77e1eff3dd0d6bd0d15cbe217
CVE-2025-63811CVE-2026-1229auth/awsauth/certcloudflare/circldependency-upgradeedwards25519golanghashicorpopentelemetryreleasesecurityvault

What happened

HashiCorp Vault v1.21.x releases (notably v1.21.4) include multiple security-related dependency upgrades and fixes. v1.21.4 upgrades cloudflare/circl to v1.6.3 to address CVE-2026-1229 (GHSA-q9hv-hpm4-hj6x), upgrades filippo.io/edwards25519 to v1.1.1 (GO-2026-4503), and updates go.opentelemetry.io/otel/sdk to v1.40.0 (GO-2026-4394). Earlier v1.21.3 fixed an auth/cert renewal validation to ensure renewed certificates match the session certificate. v1.21.2 updated golang/x/crypto to v0.45.0 to address GHSA-f6x5-jh6r-wrfv, GHSA-j5w8-q4qc-rx2x and related GO-2025 issues. v1.21.1 fixed an auth/aws‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hashicorp_vault_releases
Record identifier
3b2d27b00e61fd2cba175270d14624a0ba98e9e77e1eff3dd0d6bd0d15cbe217
Enrichment time
2026-03-20T08:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.