v1.21.4

2026-03-05T08:52:12Z534f21c14aeacad28a162e5f7a15d1d08114d597992d21d7358f973ca3e07552
CVE-2025-63811auth-awsbuild-artifactscryptodependency-upgradegohashicorpjose2goreleasesecurityvaultvulnerability-fix

What happened

HashiCorp Vault 1.21.x release notes. Notable security fixes: v1.21.1 fixes an auth/aws caching issue that could allow authentication bypass; v1.21.1 also updates/mitigates CVE-2025-63811 in jose2go. v1.21.2 updates Go crypto and other Go dependencies to address GHSA-f6x5-jh6r-wrfv, GHSA-j5w8-q4qc-rx2x and related GO-2025 advisories (GO-2025-4134, GO-2025-4135). Multiple releases are build/artifact updates (v1.21.3, v1.21.4). Recommended action: upgrade to the latest 1.21.x release containing these fixes (or apply vendor-recommended patches) and review auth/aws configurations and dependency CV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hashicorp_vault_releases
Record identifier
534f21c14aeacad28a162e5f7a15d1d08114d597992d21d7358f973ca3e07552
Enrichment time
2026-03-05T08:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.