CVE-2025-55000
MEDIUMDescription
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's TOTP secrets engine could accept valid codes multiple times rather than strictly-once. This was caused by unexpected normalization in the underlying TOTP library. To work around, ensure that all codes are first normalized before submitting to the OpenBao endpoint. TOTP code verification is a privileged action; only trusted systems should be verifying codes.
Is your site exposed to CVE-2025-55000?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| openbao | openbao |
References
Frequently Asked Questions
What is CVE-2025-55000? +
How severe is CVE-2025-55000? +
What products are affected by CVE-2025-55000? +
How do I check if I'm vulnerable to CVE-2025-55000? +
Related Vulnerabilities
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In …
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. …
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true …
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new …
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In …
OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable …