Cyber Resilience

CVE-2024-8185

Hashicorp Vault 1.2.0 – 1.16.12

Published
31 October 2024
Modified
13 November 2025
Patch / advisory
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0048 39th percentile
Risk Priority 59 floored blend · peak EPSS

Summary

CVE-2024-8185 is a high-severity Failing Open (CWE-636) vulnerability in Hashicorp Vault. Its CVSS base score is 7.5 (High).

Operationally, ranked at the 39th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to CP-12 (Safe Mode) and SC-24 (Fail in Known State) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to…

more

the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself. This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-4166Same product: Hashicorp Vault
CVE-2024-9180Same product: Hashicorp Vault
CVE-2024-7594Same product: Hashicorp Vault
CVE-2024-2048Same product: Hashicorp Vault
CVE-2024-2660Same product: Hashicorp Vault
CVE-2026-5052Same product: Hashicorp Vault
CVE-2024-5798Same product: Hashicorp Vault
CVE-2025-6000Same product: Hashicorp Vault
CVE-2024-0831Same product: Hashicorp Vault
CVE-2025-6004Same product: Hashicorp Vault

Affected Assets

hashicorp
vault
1.18.0 · 1.2.0 — 1.16.12 · 1.2.0 — 1.18.1 · 1.17.0 — 1.17.8
openbao
openbao
≤ 2.0.3

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V3.2.1
  • V7.4.1
  • V8.3.3
  • V10.3.4

Mitigating Controls (NIST 800-53 r5) AI

SC-24 directly requires the system to fail to a known state that preserves security properties, structurally stopping fallback to a less-secure mode.

SI-17 mandates explicit fail-safe procedures that activate on indicated failures, preventing the insecure fallback behavior.

CP-12 forces entry into a safe mode on detected conditions, limiting exposure but not covering every failure path.

SA-8 requires application of engineering principles that include fail-secure design, reducing the likelihood the weakness is introduced.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure-development practices explicitly include designing error and failure handling to remain in a secure state.

PR.AA-05 partial match
prevents

Least-privilege policy and enforcement directly counters the permissive-access fallback example in the CWE.

PR.PS-01 partial match
prevents

Hardened baselines and configuration management reduce the chance that error paths default to insecure settings.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

The control forces an explicit evaluation step before any response, reducing the chance that a failure condition will default to an unsafe open state.

References