{"schema_version":"1.7.3","id":"GHSA-ghfh-fmx4-26h8","published":"2025-10-22T19:37:53Z","modified":"2026-07-27T09:11:42.734128339Z","aliases":["BIT-openbao-2025-62513","CVE-2025-62513","GO-2025-4049"],"summary":"OpenBao leaks HTTPRawBody in Audit Logs","details":"### Impact\n\nOpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd).  This impacted the following subsystems:\n\n - When using the ACME functionality of PKI, this would result in short-lived ACME verification challenge codes being leaked in the audit logs.\n - When using the OIDC issuer functionality of the identity subsystem, auth and token response codes along with claims could be leaked in the audit logs.\n\nThird-party plugins may be affected.\n\n### Patches\n\nOpenBao v2.4.2 will patch this issue.\n\n### Workarounds\n\nIf users do not use the above functionality, they are not impacted. ACME verification codes are not usable after verification or challenge expiry so are of limited long-term use.","affected":[{"package":{"name":"github.com/openbao/openbao","ecosystem":"Go","purl":"pkg:golang/github.com/openbao/openbao"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-20241114205727-b1235e585db7"},{"fixed":"0.0.0-20251022165510-cc2c476bac66"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-ghfh-fmx4-26h8/GHSA-ghfh-fmx4-26h8.json"}}],"references":[{"type":"WEB","url":"https://github.com/openbao/openbao/security/advisories/GHSA-ghfh-fmx4-26h8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62513"},{"type":"WEB","url":"https://github.com/openbao/openbao/commit/cc2c476bac66e1d94776c2629793daec3af625f8"},{"type":"PACKAGE","url":"https://github.com/openbao/openbao"}],"database_specific":{"cwe_ids":["CWE-532"],"github_reviewed":true,"github_reviewed_at":"2025-10-22T19:37:53Z","nvd_published_at":"2025-10-22T20:15:38Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}