User Lockout Bypass Vulnerability in OpenBao by OpenBao
CVE-2025-54998
What is CVE-2025-54998?
In OpenBao versions ranging from 0.1.0 to 2.3.1, a significant security flaw has been identified that allows attackers to bypass the automatic user lockout mechanisms specifically within the Userpass and LDAP authentication systems. This vulnerability arises due to inconsistencies in aliasing between the pre-flight and full login request user entity alias configurations. The issue has been addressed in version 2.3.2. To mitigate risks while users upgrade to the latest version, it is advisable to implement rate-limiting quotas on the affected authentication endpoints.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openbao >= 0.1.0, < 2.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
