🔐 CVE Alert

CVE-2025-13357

HIGH 7.4

Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method

CVSS Score
7.4
EPSS Score
0.1%
EPSS Percentile
26th

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.

CWE CWE-1188
Vendor hashicorp
Product tooling
Published Nov 21, 2025
Last Updated Apr 17, 2026
Stay Ahead of the Next One

Get instant alerts for hashicorp tooling

Be the first to know when new high vulnerabilities affecting hashicorp tooling are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

HashiCorp / Tooling
4.2.0 < 5.5.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
discuss.hashicorp.com: https://discuss.hashicorp.com/t/hcsec-2025-33-vault-terraform-provider-applied-incorrect-defaults-for-ldap-auth-method/76822

Credits

This issue was identified by a third party who reported it to HashiCorp.