CVE-2025-52893
Last modified
CVE-2025-52893 is a medium-severity vulnerability rated 4.5/10 on the CVSS scale. OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive information in logs when processing malformed data. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive information in logs when processing malformed data. This is separate from the earlier HCSEC-2025-09 / CVE-2025-4166. This issue has been fixed in OpenBao v2.3.0 and later. Like with HCSEC-2025-09, there is no known workaround except to ensure properly formatted requests from all clients.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openbao | Openbao | < 2.3.0 |
References
- https://github.com/go-viper/mapstructure/pull/105Not Applicable
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-52893?
How severe is CVE-2025-52893?
How do I fix CVE-2025-52893?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-52888Allure 2 is the version 2.x branch of Allure Report, a multi…7.5
- CVE-2025-52889Incus is a system container and virtual machine manager. Whe…3.4
- CVE-2025-5289The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipboo…5.4
- CVE-2025-52890Incus is a system container and virtual machine manager. Whe…8.1
- CVE-2025-52891ModSecurity is an open source, cross platform web applicatio…6.5
- CVE-2025-52892EspoCRM is a web application with a frontend designed as a s…6.5
- CVE-2025-52894OpenBao exists to provide a software solution to manage, sto…7.5
- CVE-2025-52895Frappe is a full-stack web application framework. Prior to v…7.5
- CVE-2025-52896Frappe is a full-stack web application framework. Prior to v…5.4
- CVE-2025-52897GLPI is a Free Asset and IT Management Software package. In …6.1
- CVE-2025-52898Frappe is a full-stack web application framework. Prior to v…8.8
- CVE-2025-52899Tuleap is an Open Source Suite created to facilitate managem…5.3
Are you affected by CVE-2025-52893?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
