CVE-2025-4166 - CVE House
Back to Database
Status published Medium CVE-2025-4166

Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin

Vulnerability Description

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4166

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Vault, Vault Enterprise
Vulnerable Versions:
0.3.0, 0.10.0

Timeline

Official Publish: May 2nd, 2025
Last Modified: May 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)