AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-4166

MEDIUM · CVSS 4.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-05-02 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.5. See the original NVD description below for full technical details.

CVE
CVE-2025-4166
Severity
MEDIUM
CVSS
4.5
EPSS
0.43%

Original NVD Description

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

Related CVEs

Other vulnerabilities affecting the same vendor(s)