{"id":"src_coGbfea_Z3j65BYWatepR","slug":"vault-releases","name":"Vault","type":"github","url":"https://github.com/hashicorp/vault","orgId":"org_Yj55_xJFX2PSbzXjXof_V","productId":"prod_9BQfJd7bY4lhYa3ranZLC","productSlug":"vault","org":{"id":"org_Yj55_xJFX2PSbzXjXof_V","slug":"hashicorp","name":"HashiCorp"},"isPrimary":false,"isHidden":false,"discovery":"curated","metadata":"{\"evaluatedMethod\":\"github\",\"evaluatedAt\":\"2026-04-07T23:43:09.050Z\",\"changelogUrl\":\"https://github.com/hashicorp/vault/blob/HEAD/CHANGELOG.md\",\"changelogDetectedAt\":\"2026-04-08T00:16:44.570Z\",\"wellKnownSweptAt\":\"2026-10-01T06:01:26.362Z\",\"sourceActor\":{\"nextAlarmAt\":\"2026-10-09T07:19:18.932Z\",\"lastAlarmAt\":\"2026-10-08T07:19:19.482Z\",\"managed\":true}}","notice":null,"kind":"platform","stars":36352,"starsFetchedAt":"2026-10-08T07:27:33.255Z","releaseCount":95,"releasesLast30Days":2,"avgReleasesPerWeek":0.3,"latestVersion":"v2.1.2","latestDate":"2026-10-07T13:31:18.000Z","changelogUrl":"https://github.com/hashicorp/vault/blob/HEAD/CHANGELOG.md","hasChangelogFile":true,"lastFetchedAt":"2026-10-08T07:27:33.255Z","lastPolledAt":"2026-10-08T07:22:27.674Z","changeDetectedAt":null,"trackingSince":"2023-02-06T16:44:53.000Z","releases":[{"id":"rel_odFFBuQta3xGX1V-D_gvc","version":"v2.1.2","type":"feature","title":"v2.1.2","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2026-10-07T13:31:18.000Z","fetchedAt":"2026-10-08T07:22:29.233Z","url":"https://github.com/hashicorp/vault/releases/tag/v2.1.2","media":[],"coverageCount":0},{"id":"rel_Kv8orv_AdvBO_P7VwbMQk","version":"v2.1.1","type":"feature","title":"v2.1.1","summary":"Updates github.com/apache/thrift to v0.24.0, golang.org/x/crypto to v0.56.0, and google.golang.org/grpc to v1.83.2 to fix ghsa-8wv5-x4w7-5gww, GO-2026-6354, GO-2026-6355, and GHSA-2v4p-qf9q-27wj. Also fixes auth/token/lookup returning 403 for JWT tokens in non-root namespaces, a panic in `vault recover` without a path, and OIDC identity token billing units computed incorrectly across periodic flush cycles.","titleGenerated":"Vault v2.1.1 patches three dependency CVEs and fixes PKI, token, and OIDC billing bugs","titleShort":"Thrift, x/crypto, gRPC CVEs patched; JWT token lookup unblocked","breaking":"minor","importance":3,"content":"## 2.1.1\r\n### September 16, 2026\r\n\r\nSECURITY:\r\n\r\n* core: Update github.com/apache/thrift to v0.24.0 to fix security vulnerability ghsa-8wv5-x4w7-5gww.\r\n* core: Update golang.org/x/crypto to v0.56.0 to fix security vulnerabilities GO-2026-6354 and GO-2026-6355.\r\n* core: Update google.golang.org/grpc to v1.83.2 to fix security vulnerability GHSA-2v4p-qf9q-27wj.\r\n\r\nCHANGES:\r\n\r\n* auth/jwt: Added Okta provider with group fetching from Admin API when fetch_groups=true and truncation is detected.\r\n* auth/jwt: Update plugin to [v0.26.4](https://github.com/hashicorp/vault-plugin-auth-jwt/releases/tag/v0.26.4)\r\n* core/raft: Limited concurrent retry-join workers to 20. Any further retry-join attempts while 20 are in progress will result in an error (`too many concurrent raft retry joins in progress`).\r\n* core: Bump Go version to 1.26.8\r\n\r\nIMPROVEMENTS:\r\n\r\n* secrets import: Add `allowed_ipv4_cidrs` to `source_aws` and `source_azure` Secrets Import blocks to allow private CIDR exemptions for SSRF-safe connectivity.\r\n* secrets/pki: add an additional field to include an RFC 5280 revocation reason for (/pki/revoke) and (/pki/revoke-with-key).\r\n* ui: Bump dompurify to 3.4.15 to address SECVULN advisories\r\n\r\nBUG FIXES:\r\n\r\n* Secrets Recovery (enterprise): Fixing Vault panic in cli when running `vault recover` without a path.\r\n* auth/jwt: Fixed incorrect HTTP status codes returned during agent ceiling policy evaluation.\r\n* auth/token: Fixed a bug where `auth/token/lookup` and `auth/token/lookup-self` returned 403 for JWT tokens in a non-root namespace.\r\n* consumption-billing: Fix OIDC identity token billing units being computed incorrectly across periodic flush cycles. The billing scalar now applies per-token duration adjustment, so the reported scalar and the per-mount attribution breakdown are always consistent.\r\n* core/activitylog (enterprise): Fix a panic in CensusReport ACL policy metrics collection by safely handling transient missing policies and nil policy path/permission data while policies are changing.\r\n* core/mounts: Fixed `vault secrets move` (and `vault auth move`) incorrectly placing a mount in the root namespace when the destination path has a leading slash.\r\n* oauth-resource-server (enterprise): Fix issue where RAR enforcement was skipped when the token's `iss` claim had cosmetic differences (e.g. different casing or trailing slash) compared to the issuer stored in the resource server profile.\r\n* plugins: Fix issue with `vault plugin reload -mounts` command when run in the root namespace\r\n* secrets-sync (enterprise): Fix `LIST /v1/sys/sync/associations` intermittently returning zero associations/secrets by forwarding the request to the active node instead of allowing it to be served locally by a performance standby or performance secondary.\r\n* secrets/pki (enterprise): Fix panic in CMPv2 sentinel field parsing when cert request messages are empty.\r\n* secrets/pki (enterprise): Fix unified CRL not being rebuilt after the background transfer copies locally-revoked certificates into unified storage.\r\n* ui: Fix agent registry ceiling policies not displaying due to incorrect property name\r\n* ui: Fix total secrets count binding on secrets sync overview page to match the API response key.\r\n* ui: Resolve the flickering on the login page when a trailing slash is added to the namespace in the field.","publishedAt":"2026-09-16T21:04:32.000Z","fetchedAt":"2026-09-17T06:15:59.608Z","url":"https://github.com/hashicorp/vault/releases/tag/v2.1.1","media":[],"coverageCount":0},{"id":"rel_9HDF-v31CXbquGfMC8wwY","version":"v2.1.0","type":"feature","title":"v2.1.0","summary":"Adds automatic DNS-01 challenge fulfillment for PKI external CA via AWS Route53, Azure DNS, Google Cloud DNS, and RFC2136-compliant servers, plus PKCS#12/JKS bundle support and Agent Registry UI (enterprise). SLH-DSA now joins ECDSA/Ed25519 for hybrid sign/verify in the Transit engine. Two critical security patches, a denied-issuer-id mutation guard, and several data-loss-tier fixes including a Nomad connection-pool fix and SQL-injection sanitization in database username templates.","titleGenerated":"Vault v2.1.0 adds PKI DNS-01 automation and SLH-DSA transit support","titleShort":"Automatic PKI DNS-01 challenges; SLH-DSA hybrid sign/verify","breaking":"major","importance":4,"content":"## 2.1.0\r\n### September 01, 2026\r\n\r\nSECURITY:\r\n\r\n* core: Update go.etcd.io/etcd/client/pkg/v3 to v3.7.1 to fix security vulnerability GO-2026-6107.\r\n* core: Update software.sslmate.com/src/go-pkcs12 to v0.7.2 to fix security vulnerability GO-2026-5052.\r\n\r\nCHANGES:\r\n\r\n* License: Add Agentic IAM terms to client licensing model and update terms for Vault Platform licensing model.\r\n* core: Bump Go version to 1.26.7.\r\n* oauth-resource-server (enterprise): Prevent issuer_id from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the issuer_id.\r\n* oauth-resource-server (enterprise): Prevent unique_id_claim from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the unique_id_claim.\r\n* oauth-resource-server (enterprise): The OAuth Resource Server feature no longer requires activation via the `sys/activation-flags/oauth-resource-server/activate` endpoint.\r\n* oauth-resource-server (enterprise): Update OAuth Resource Server config to include custom claim options for the token's unique identifier and actor.\r\n* secrets/openldap (enterprise): Update plugin to [v0.18.4+ent](https://github.com/hashicorp/vault-plugin-secrets-openldap/releases/tag/v0.18.4+ent)\r\n\r\nFEATURES:\r\n\r\n* **Agent Registry UI (enterprise)**: Adds a new Agentic Security section to the primary navigation with an Agent Registry page where operators can view, search, and manage registered AI agents, their associated Vault entities and aliases, assigned policies, and operational status.\r\n* **Automatic DNS-01 Challenge Fulfillment for PKI External CA**: Integrate with the following DNS providers for automatic DNS-01 challenge fulfillment: AWS Route53, Azure DNS, Google Cloud DNS, and BIND and other RFC2136-compliant servers.\r\n* **PKI PKCS#12 and JKS Support**: Adds support for PKCS#12 (PFX) and Java keytool (JKS) certificate bundles to relevant PKI endpoints. Bundles are returned as base64-encoded, password-protected files.\r\n* **SLH-DSA support for Hybrid sign/verify in Transit engine (enterprise)**: Add support for SLH-DSA as the PQC component for Hybrid sign/verify operations. This is compatible with both ECDSA (p-256, P-384, P-521) and Ed25519.\r\n* secrets/pki-external-ca (enterprise): Add support for handling dns-01 challenges for Azure, AWS, GCP, and rfc2136 DNS.\r\n\r\nIMPROVEMENTS:\r\n\r\n* agent-registry (enterprise): Removed the restriction that disallowed the use of 'deny' in ceiling policies, resulting in request errors.\r\n* agent/pkiexternalca: Replace go.uber.org/atomic with sync/atomic (stdlib) for atomic boolean operations in the pkiexternalca package.\r\n* auth/token: Add global denylist for revoking OAuth JWTs to prevent authorization of specific tokens across all namespaces.\r\n* core/seal (enterprise): Update Oracle Cloud library to enable seal integration with newer regions.\r\n* ui: Bump `dompurify` from `3.4.6` to `3.4.13`.\r\n* ui: Bump shell-quote from 1.8.4 to 1.9.0.\r\n* ui: Exposing the RSA Private Key field in the UI when generating credentials with the snowflake database secrets engine. Previously, this field was only shown in the cli.\r\n* ui: Secrets engine delete confirmation modal now requires typing `delete-engine` to confirm, displays the engine name, secret count (KV engines only), and a list of what will be permanently deleted. ConfirmModal has now been updated to include a optional type-to-confirm.\r\n\r\nBUG FIXES:\r\n\r\n* agent/pki-external-ca: Fix CA chain extraction from Vault PKI API responses where `ca_chain` field was always empty in templates due to incorrect type handling of array responses\r\n* api: Account for the HTTP Age header when calculating a lease's remaining lifetime, so that leases read or renewed through a caching proxy such as Vault Agent are renewed before they expire.\r\n* core (enterprise): Fix a data race and potential panic during seal/unseal\r\n* core (enterprise): Fix panic in `collectOperatorImportMetrics` when `router.Route` returns a nil response with no error during KVv2 metadata reads on performance secondary nodes. This condition occurs during the WAL-stream partial-sync phase of an initial join.\r\n* core/login: Fix panic on malformed login requests. Vault now returns an error for malformed login payloads instead of dropping the client connection (no data loss).\r\n* core/metrics: Fixed a bug where log_format = \"json\" had no effect on telemetry sink errors from statsd and statsite backends.\r\n* core/wrapping: sys/wrapping/wrap now enforces uuid-format wrapping tokens, ignoring any caller-requested wrap format.\r\n* core: Fix `vault operator migrate -start` command when migrating to raft integrated storage.\r\n* core: vault kv put/get now works with external OAuth tokens.\r\n* cubbyhole: Fix cubbyhole writes for JWT tokens in non-root namespaces\r\n* default-auth: Fix issue with legacy default-auth configs that would break as part of upgrading to a newer version of Vault.\r\n* identity: Fixed entity alias creation failing with \"mount accessor namespace does not match request namespace\" when using a synthetic mount accessor in a namespaced context\r\n* oauth-resource-server (enterprise): Fix issue where `optional_authorization_details` was incorrectly ignored for delegated (OBO) workflows when the subject has no agent registration, resulting in RAR not being mandatory in those requests.\r\n* plugins: Reading a versioned-only plugin without specifying `-version` now auto-selects it when only one version exists, or returns an error listing available versions, instead of a silent 404.\r\n* proxy/cache (enterprise): Fixed a bug in the static secret cache where `GET` requests with `?list=true` were incorrectly cached and served stale.\r\n* sdk/rotation: Subsequent calls will no longer allow both the `rotation_period` and `rotation_schedule` fields to be set simultaneously. The SDK now explicitly empties the opposing field to guarantee mutual-exclusion.\r\n* secret/pki: Fix ACME order finalize race condition where concurrent requests could double-issue certificates and orphan one from order-keyed tracking\r\n* secret/pki: prevent key rename from accepting a name already held by a different key.\r\n* secrets/database: Sanitize the caller-controlled DisplayName before it is used in generated usernames to prevent SQL injection via username templates. Adds a configuration warning when a username_template references DisplayName without a truncate function.\r\n* secrets/ldap: manually rotating a static role password will restart the rotation TTL once again, matching the behavior prior to v2.0.0\r\n* secrets/nomad: Fix connection exhaustion under high concurrency by introducing a shared, pooled HTTP client with a per-host connection cap. Previously, a new TCP connection was opened for every credential request, causing Nomad to return HTTP 429 \"too many concurrent connections\" errors when more than 100 leases were generated simultaneously.\r\n* serviceregistration/consul: Fixed an issue where Vault would permanently deregister itself from the Consul service catalog when a SIGHUP/reload signal was sent and the configuration used Consul as the storage backend without an explicit `service_registration` stanza.\r\n* ui/secrets/pki: Fix issuers list page failing to load when issuer count exceeds 10\r\n* ui: Fix 403 error on auth method Configure page for policies that grant read on sys/auth* but not sys/auth/*.\r\n* ui: Fix Kubernetes auth method not saving `token_reviewer_jwt` — the wrong OpenAPI schema key (`KubernetesConfigureRequest`) was used instead of `KubernetesConfigureAuthRequest`, causing the JWT field to be omitted from the form and API payload on save.\r\n* ui: Fix border clipping on dashboard widget tables by applying overflow-hidden styling.\r\n* ui: Fix open redirect bug in OIDC provider route.\r\n* ui: Fix policy generator flyout rejecting saves when no capabilities are selected for a rule.\r\n* ui: add totalItems property to fix filtered list pagination showing incorrect total page count\r\n* ui: fix spurious \"No access\" banner when navigating to Vault UI with `?namespace=root` in the URL","publishedAt":"2026-09-01T14:37:47.000Z","fetchedAt":"2026-09-02T05:28:34.115Z","url":"https://github.com/hashicorp/vault/releases/tag/v2.1.0","media":[],"coverageCount":0},{"id":"rel_sH-XRuZk3LrbPkR5FWmU7","version":"v2.0.4","type":"feature","title":"v2.0.4","summary":"Fixed a privilege-escalation vulnerability where a denied_parameters constraint on the policies field could be bypassed with mixed-case policy names; Vault now normalizes to lowercase. Also removed gnupg, openssl, and procps from UBI container images, and dropped support for duplicate HCL attributes. Plus many enterprise and OSS bug fixes across billing, audit, identity, and SCIM.","titleGenerated":"Vault v2.0.4 fixes privilege-escalation ACL bypass and removes UBI packages","titleShort":"ACL bypass via mixed-case policies fixed; UBI packages removed","breaking":"major","importance":4,"content":"## 2.0.4\r\n### August 04, 2026\r\n\r\nBREAKING CHANGES:\r\n\r\n* containers: The following packages have been removed from UBI based container\r\nimages: gnupg, openssl, procps.\r\n\r\nSECURITY:\r\n\r\n* acl: Fix privilege-escalation vulnerability where a `denied_parameters` constraint on the `policies` request field could be bypassed by submitting a mixed-case policy name (e.g. \"Super-Admin\" instead of \"super-admin\"). Vault now normalizes the `policies` parameter to lowercase before evaluating `allowed_parameters`/`denied_parameters` constraints.\r\n* identity/scim (enterprise): The `identity/entity/merge` endpoint now rejects requests that involve any SCIM-managed entity, preventing privileged operators from bypassing SCIM ownership guardrails to transfer aliases, group memberships, or policies across SCIM boundaries.\r\n* identity: Prevent the entity batch-delete endpoint (identity/entity/batch-delete) from deleting the underlying storage of entities that belong to another namespace.\r\n* identity: entity/name updates now reject mismatched id or external_id selectors to prevent retargeting updates to a different entity\r\n\r\nCHANGES:\r\n\r\n* auth/oci: Update plugin to [v0.21.3](https://github.com/hashicorp/vault-plugin-auth-oci/releases/tag/v0.21.3)\r\n* core: Bump Go version to 1.26.5.\r\n* core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with\r\nduplicate attributes now always fails, and the VAULT_ALLOW_PENDING_REMOVAL_DUPLICATE_HCL_ATTRIBUTES environment\r\nvariable that previously restored the legacy behavior has been removed.\r\n\r\nFEATURES:\r\n\r\n* secrets: Added ability to view secrets in YAML format\r\n\r\nIMPROVEMENTS:\r\n\r\n* auth/cert: Support login via x-forwarded cert headers even with tls disabled on the vault listener.\r\n* core (enterprise): Add an endpoint at `sys/config/oauth-resource-server/id/:config_id` to read oauth resource server profiles by `config_id`\r\n* core (enterprise): Make OAuth resource server JWT `typ` validation more permissive for tokens from IdPs such as Okta by allowing a missing `typ` header, while restricting present `typ` values to `at+jwt`, `application/at+jwt`, and `JWT`.\r\n* core (entreprise): Ameriolate sealwrap lock contention for core paths.\r\n* core/acl: Adds a global `deny_slash_in_templated_path` configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to `false`.\r\n* core/identity: Adds a global `deny_slash_in_templated_path` configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to `false`.\r\n* core/managed-keys/PKCS#11 (enterprise): Providing a non-empty value for one field while the other is already saved is rejected. To switch addressing modes, you must explicitly clear the old field by sending it as an empty string (\"\") in the same request alongside the new value.\r\n* core/managed-keys/PKCS#11 (enterprise): slot and token_label are now strictly enforced as mutually exclusive identifiers for an HSM token\r\n* events: Add `VAULT_EVENT_NOTIFICATIONS_BOUNDED_QUEUE_SIZE` environment variable to configure bounded event queues for event notification subscribers. Set to a positive integer (e.g., 16) to enable buffered channels of that size (maximum 1000). This prevents resource exhaustion in deployments with high subscriber counts, but comes at the cost of the potential for subscribers to miss events. Defaults to 0 (unbuffered) for backward compatibility.\r\n* identity/scim (enterprise): Added filtering support to the `GET /scim/v2/Users` and `GET /scim/v2/Groups` endpoints per RFC 7644. Supported filters: `userName eq`, `externalId eq`, `active eq`, and `meta.lastModified gt/ge/lt/le` for Users; `displayName eq` and `meta.lastModified gt/ge/lt/le` for Groups. Unsupported filter expressions return HTTP 400. `ServiceProviderConfig` now advertises `filter.supported: true`.\r\n* identity/scim (enterprise): Improve SCIM User and Group listing endpoint performance by using prefix sort instead of a separate sort pass.\r\n* identity: Include entity status and entity/alias timestamp details in entity list key_info responses.\r\n* oauth-resource-server: Add support for fine-grained policy control options (parameter constraints) in Rich Authorization Requests (RAR), including `allowed_parameters`, `denied_parameters`, and `required_parameters` inside `authorization_details`.\r\n* oauth-resource-server: Add support for identity template expressions (e.g. `{{identity.entity.id}}`) in Rich Authorization Requests (RAR).\r\n* scim: User resources now include a read-only `groups` field listing the direct group memberships managed by the requesting SCIM client, per RFC 7643.\r\n* secrets/kv (enterprise): Support reading and recovering KVv2 secrets from a loaded snapshot, including in-place recover and copy-from-path within the same mount and namespace.\r\n* ui: Add a read-only YAML view option to the KV v2 secret details page, alongside the existing UI and JSON views.\r\n* ui: Bump pnpm.overrides entry for `tmp` from 0.2.6 to 0.2.7.\r\n* ui: Bump pnpm.overrides entry for `ws` from 8.20.1 to 8.21.0.\r\n\r\nBUG FIXES:\r\n\r\n* Proxy/Agent: Fixed a bug where auth method headers accumulated on the shared API client across re-auth cycles.\r\n* Proxy: Fixed a bug where the Vault token header accumulated duplicate values across WebSocket reconnects in the static secret cache updater.\r\n* Secrets Recovery (enterprise): Do not redirect to the active node for list requests to `sys/storage/raft/snapshot-load` or read/delete requests to `sys/storage/raft/snapshot-load/{id}`. If possible, handle these requests on the performance standby, otherwise forward the requests to the active node.\r\n* audit: Fix a regression from CVE-2025-6000 that broke enabling audit devices on Windows when a plugin directory was configured.\r\n* audit: make file and socket audit sink serialization context-aware so canceled or expired requests stop waiting behind blocked audit writes, reducing buildup of goroutines, memory, connections, and file descriptors during audit sink contention\r\n* auth/cert: Add support for x-forwarded cert headers coming from AWS ALBs.\r\n* auth/spiffe (enterprise): Use the full peer certificate chain when verifying certificates.\r\n* aws/auth: Redact EC2 instance metadata values from AWS auth error messages.\r\n* consumption-billing: Fix bug where PKI, SSH and SSH OTP certificate billing units from performance standby nodes were not being forwarded to active nodes for storage, causing billing events on standby nodes to be lost.\r\n* consumption-billing: Fix bug where SPIFFE JWT token billing units from performance standby nodes were not being forwarded to active nodes for storage, causing billing events on standby nodes to be lost.\r\n* consumption-billing: Fixed a bug where SSH duration-adjusted certificate counts and OTP counts whose decimal representation began with '4' could not be read back from storage, causing `sys/billing/overview` to return a 500 error with \"lz4: bad magic number\". The storage encoding now uses plain decimal strings consistent with other billing metrics, avoiding misidentification as lz4-compressed data.\r\n* consumption-billing: Fixed bug where OIDC token duration counts from performance standby nodes were not forwarded to active nodes for storage, causing billing events on standby nodes to be lost.\r\n* consumption-billing: Fixed deadlocks in KMIP and mount-scanning billing paths by avoiding nested lock acquisition during mount and plugin enumeration.\r\n* consumption-billing: Fixes LDAP and OpenLDAP dynamic and static role counting in use-case billing \r\nto use dedicated count endpoints (role-count, static-role-count) instead of LIST-based counting, which was undercounting roles.\r\n* core (enterprise): Fix a bug that causes unnecessary seal rewrapping.\r\n* core (enterprise): Preserve wrapping metadata when Control Group unwrap replays an approved request that returns a wrapped response.\r\n* core (enterprise): Update state checking of Sever-Side Consistent Token (SSCT) when used on performance secondary clusters. 403 response codes will be preferred over 412 for invalid, cross cluster token requests to secondary active nodes.\r\n* core/managed-keys (enterprise): Allow slot numbers above 32 bits in PKCS#11 managed keys.\r\n* core/seal: Fixed goroutine leak occurring when Encryption and Decryption functions time out.\r\n* core: Preserve URL query parameters when redirecting API requests containing duplicate slashes to their canonical path.\r\nPreviously, the redirect dropped parameters such as `?list=true`, potentially changing the result of the request.\r\n* events (enterprise): Fix a bug where events stopped being forwarded to performance secondaries after the active node restarted or had a change event (seal/unseal, etc).\r\n* export API: Normalize the end_time parameter in the activity export API to the end of the month to match the behavior stated in the documentation.\r\n* oauth-resource-server (enterprise): OAuth Resource Server authorization now treats an empty `authorization_details` array like an absent claim when authorization details are optional. Previously, tokens containing an empty array were rejected with `RAR_NO_MATCH` instead of continuing through normal identity and policy authorization.\r\n* secrets-sync (enterprise):fixed incorrect error response code mapping for GCP Secrets Sync Customer Controlled Encryption validations, which were returned as 500 Internal Server Error instead of 400 Bad Request.\r\n* secrets-sync: Fix GCP Secret Manager destinations losing their per-region KMS key on Vault restart.\r\n* secrets-sync: Fixes Custom Tags field in Details view to display keys with empty value\r\n* secrets/pki-external-ca (enterprise): Include the private key within the certificate API response field's PEMs when certificate_format is set to pem_bundle\r\n* secrets/transit (enterprise): Add managed key support to CSR sign and set certificate chain endpoints.\r\n* ui: Correctly handle string values (\"true\"/\"false\") for `tls_disable` when displaying TLS status in the Cluster Configuration widget.\r\n* ui: Fixes PKI generate root so Not valid after correctly controls cert expiration inputs.","publishedAt":"2026-08-04T18:34:44.000Z","fetchedAt":"2026-08-05T04:00:19.646Z","url":"https://github.com/hashicorp/vault/releases/tag/v2.0.4","media":[],"coverageCount":0},{"id":"rel_Kxk8EOqmbTPuQLpbNI5ws","version":"v2.0.3","type":"feature","title":"v2.0.3","summary":"LIST requests with a trailing slash now correctly respect more-specific deny policies, fixing an ACL bypass where a request to `LIST kv/private/` could skip a `deny` on `kv/*`. Also introduces beta support for AI agents in Enterprise, including an agent registry and OAuth resource server capabilities. Plus a constant-time recovery token comparison and several security fixes across RADIUS, SPIFFE, and transform.","titleGenerated":"Vault v2.0.3 fixes ACL bypass via trailing-slash LIST requests and adds AI agent support (Enterprise Beta)","titleShort":"Trailing-slash LIST no longer bypasses ACL deny; AI Agent support in Beta","breaking":"unknown","importance":null,"content":"SECURITY:\r\n\r\n* auth/radius: Added case_insensitive_names toggle to prevent username collisions and enable case-insensitive user handling.\r\n* core/acl: Fix LIST ACL bypass where a trailing-slash request could skip a more-specific deny rule.\r\n* core: Use constant-time recovery token comparison\r\n* secrets/spiffe (enterprise): Ensure template values are properly escaped.\r\n* transform (enterprise): Add appropriate db specific quoting and escaping.\r\n\r\nCHANGES:\r\n\r\n* auth/cf: Update plugin to [v0.23.1](https://github.com/hashicorp/vault-plugin-auth-cf/releases/tag/v0.23.1)\r\n* core/acl: LIST requests with a trailing slash now correctly respect more-specific deny policies. Previously, a deny on `path \"kv/*\" { deny }` could be bypassed for `LIST kv/private/` if a broader allow `path \"kv/*\"` also existed. Policies relying on the previous (incorrect) behavior may now be denied.\r\n* core: Vault will now redirect non-canonicalized paths (containing `/./`, `/../`, or `//`) to a cleaned path, instead of rejecting these requests\r\n* secrets/azure: Update plugin to [v0.26.5+ent](https://github.com/hashicorp/vault-plugin-secrets-azure/releases/tag/v0.26.5+ent)\r\n\r\nFEATURES:\r\n\r\n* **AI Agent Support (Beta/Enterprise)**: Adds beta support for first-class AI agents. Adds\r\nan Agent Registry to register agents, and adds support for using Vault as an OAuth resource server\r\nfor registered agent entities. When configured, allows OAuth 2.0 JWTs to be used to directly authorize\r\nrequests to Vault, without needing a Vault token.\r\n\r\nIMPROVEMENTS:\r\n\r\n* consumption-billing: Add a new `sys/billing/config` endpoint to allow configuration of billing data retention (min 13 months, max 6 years).\r\n* core (Enterprise): Make deadlock detection in sealwrap configurable by adding \"sealwrap\" to existing configuration detect_deadlocks.\r\n* identity/scim (enterprise): Update PATCH operations on scim/v2/Users to allow multiple modifications in the same patch call, support for patch operations on user metadata and name in addition to active status, and allow specifying `path` value in patch operations\r\n* sdk/helper/keysutil: The lock manager's GetPolicy function now always returns a locked Policy, even when caching is\r\nenabled. The PolicyRequest struct has a new field to indicate whether the caller requires a write lock on the policy.\r\n* ui (enterprise): Migrate charts from Lineal to Carbon Charts in the Client usage overview and Vault usage dashboard.\r\n\r\nBUG FIXES:\r\n\r\n* core/rotationMgr: Fix storage routing for local mounts in namespaces to prevent metadata replication and ensure GDPR compliance.\r\n* kmip (enterprise): Fix a bug that prevents the legacy CA from working on a named listener.\r\n* secret-sync (enterprise): Fix GCP Secret Manager replication policy persistence across Vault restarts.\r\n* secrets/database/mssql: Deregister stale TLS configurations when MySQL connection TLS settings change or the connection is closed, preventing retained certificate pools from accumulating.\r\n* secrets/pki: Fix PKI certificate issuance not_after time to respect max TTL.\r\n* secrets/transit: Add managed key support to Transit rewrap endpoint.\r\n* storage/raft: reject `performance_multiplier` values less than or equal to zero","publishedAt":"2026-06-17T20:23:38.000Z","fetchedAt":"2026-06-18T15:03:49.568Z","url":"https://github.com/hashicorp/vault/releases/tag/v2.0.3","media":[],"coverageCount":0},{"id":"rel_ZXv3marU_AHe1heVKtvFj","version":"v2.0.2","type":"feature","title":"v2.0.2","summary":"Vault containers no longer have the cap_ipc_lock capability, preventing calls to mlock() for memory locking—operators should set disable_mlock = true in configuration and disable swapping at runtime. SSH RSA key sizes are now limited to a maximum of 8192 bits (CVE-2026-39829). Also fixed plugin signature verification failures with expired PGP keys and a transit key version dropdown state issue.","titleGenerated":"Vault v2.0.2 removes container mlock capability and limits SSH RSA key sizes","titleShort":"Container mlock disabled; SSH RSA keys capped at 8192 bits","breaking":"unknown","importance":null,"content":"BREAKING CHANGES:\r\n\r\n* containers: Remove `cap_ipc_lock` capability on `vault` at build time to allow running Vault in common container runtimes. Vault in containers will no longer be able to call `mlock()` to lock memory. Operators should set `disable_mlock = true` in Vault's configuration. Runtime operators are advised to disable swapping to guarantee data safety.\r\n* secrets/ssh: RSA key sizes are now limited to a maximum size of 8192 bits addressing CVE-2026-39829\r\n\r\nCHANGES:\r\n\r\n* core: Bump Go version to 1.26.4\r\n* secrets/azure (enterprise): Update plugin to [v0.26.4+ent](https://github.com/hashicorp/vault-plugin-secrets-azure-enterprise/releases/tag/v0.26.4+ent)\r\n\r\nBUG FIXES:\r\n\r\n* plugins: Fix plugin signature verification failure with expired pgp key when registering a plugin.\r\n* ui/transit: Fix key version dropdown selected state when editing a transit key.","publishedAt":"2026-06-05T16:26:07.000Z","fetchedAt":"2026-06-06T03:03:24.453Z","url":"https://github.com/hashicorp/vault/releases/tag/v2.0.2","media":[],"coverageCount":0},{"id":"rel_ECebbkEauMbVTBSKf5tRA","version":"v2.0.1","type":"feature","title":"v2.0.1","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2026-05-19T20:57:55.000Z","fetchedAt":"2026-05-20T11:03:33.025Z","url":"https://github.com/hashicorp/vault/releases/tag/v2.0.1","media":[],"coverageCount":0},{"id":"rel_evuMgtlGgLnofoaSR-bgt","version":"v2.0.0","type":"feature","title":"v2.0.0","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2026-04-14T20:07:04.000Z","fetchedAt":"2026-04-14T23:04:36.374Z","url":"https://github.com/hashicorp/vault/releases/tag/v2.0.0","media":[],"coverageCount":0},{"id":"rel_zG-KJfCEzhEHyeWa-rPPd","version":"v1.21.4","type":"feature","title":"v1.21.4","summary":"\r\nSECURITY:\r\n\r\n* Upgrade `cloudflare/circl` to v1.6.3 to resolve CVE-2026-1229\r\n* Upgrade `filippo.io/edwards25519` to v1.1.1 to resolve GO-2026-4503\r...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"\r\nSECURITY:\r\n\r\n* Upgrade `cloudflare/circl` to v1.6.3 to resolve CVE-2026-1229\r\n* Upgrade `filippo.io/edwards25519` to v1.1.1 to resolve GO-2026-4503\r\n* vault/sdk: Upgrade `cloudflare/circl` to v1.6.3 to resolve CVE-2026-1229\r\n* vault/sdk: Upgrade `go.opentelemetry.io/otel/sdk` to v1.40.0 to resolve GO-2026-4394\r\n\r\nCHANGES:\r\n\r\n* core: Bump Go version to 1.25.7\r\n* mfa/duo: Upgrade duo_api_golang client to 0.2.0 to include the new Duo certificate authorities\r\n* ui: Remove ability to bulk delete secrets engines from the list view.\r\n\r\nIMPROVEMENTS:\r\n\r\n* core/seal: Enhance sys/seal-backend-status to provide more information about seal backends.\r\n* secrets/kmip (Enterprise): Obey configured best_effort_wal_wait_duration when forwarding kmip requests.\r\n* secrets/pki (enterprise): Return the POSTPKIOperation capability within SCEP GetCACaps endpoint for better legacy client support.\r\n\r\nBUG FIXES:\r\n\r\n* core (enterprise): Buffer the POST body on binary paths to allow re-reading on non-logical forwarding attempts. Addresses an issue for SCEP, EST and CMPv2 certificate issuances with slow replication of entities\r\n* core/identity (enterprise): Fix excessive logging when updating existing aliases\r\n* core/managed-keys (enterprise): client credentials should not be required when using Azure Managed Identities in managed keys.\r\n* plugins (enterprise): Fix bug where requests to external plugins that modify storage weren't populating the X-Vault-Index response header.\r\n* secrets (pki): Allow issuance of certificates without the server_flag key usage from SCEP, EST and CMPV2 protocols.\r\n* secrets/pki (enterprise): Address cache invalidation issues with CMPv2 on performance standby nodes.\r\n* secrets/pki (enterprise): Address issues using SCEP on performance standby nodes failing due to configuration invalidation issues along with errors writing to storage\r\n* secrets/pki (enterprise): Modify the SCEP GetCACaps endpoint to dynamically reflect the configured encryption and digest algorithms.\r\n* secrets/pki: The root/sign-intermediate endpoint should not fail when provided a CSR with a basic constraint extension containing isCa set to true\r\n* secrets/pki: allow glob-style DNS names in alt_names.\r\n","publishedAt":"2026-03-05T06:37:01.000Z","fetchedAt":"2026-04-08T00:01:01.400Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.21.4","media":[],"coverageCount":0},{"id":"rel_W82rQVryTrA1i6w-H5E39","version":"v1.21.3","type":"feature","title":"v1.21.3","summary":"## February 05, 2026\r\n**SECURITY:**\r\n\r\nauth/cert: ensure that the certificate being renewed matches the certificate attached to the session.\r\n\r\n**CHAN...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## February 05, 2026\r\n**SECURITY:**\r\n\r\nauth/cert: ensure that the certificate being renewed matches the certificate attached to the session.\r\n\r\n**CHANGES:**\r\n\r\ncore: Bump Go version to 1.25.6\r\n\r\n**FEATURES:**\r\n\r\nUI: Hashi-Built External Plugin Support: Recognize and support Hashi-built plugins when run as external binaries\r\n\r\n**IMPROVEMENTS:**\r\n\r\ncore/managed-keys (enterprise): Allow GCP managed keys to leverage workload identity federation credentials\r\nsdk: Add alias_metadata to tokenutil fields that auth method roles use.\r\nsecret-sync (enterprise): Added telemetry counters for reconciliation loop operations, including the number of corrections detected, retry attempts, and operation outcomes (success or failure with internal/external cause labels).\r\nsecret-sync (enterprise): Added telemetry counters for sync/unsync operations with status breakdown by destination type, and exposed operation counters in the destinations list API response.\r\n\r\n**BUG FIXES:**\r\n\r\nagent: Fix Vault Agent discarding cached tokens on transient server errors instead of retrying\r\ncore (enterprise): Fix crash when seal HSM is disconnected\r\ndefault-auth: Fix issue when specifying \"root\" explicitly in Default Auth UI\r\nidentity: Fix issue where Vault may consume more memory than intended under heavy authentication load.\r\nsecrets/pki (enterprise): Fix SCEP related digest errors when requests contained compound octet strings\r\nui: Fixes login form so ?with=<path> query param correctly displays only the specified mount when multiple mounts of the same auth type are configured with listing_visibility=\"unauth\"\r\nui: Reverts Kubernetes CA Certificate auth method configuration form field type to file selector","publishedAt":"2026-03-04T22:47:38.000Z","fetchedAt":"2026-04-08T00:01:01.400Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.21.3","media":[],"coverageCount":0},{"id":"rel_JVNi0yiQtTnCzfLeRLrcp","version":"v1.21.2","type":"feature","title":"v1.21.2","summary":"## 1.21.2\r\n### January 07, 2026\r\n\r\nCHANGES:\r\n\r\n* auth/oci: bump plugin to v0.20.1\r\n* core: Bump Go version to 1.25.5\r\n* packaging: Container images ar...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.21.2\r\n### January 07, 2026\r\n\r\nCHANGES:\r\n\r\n* auth/oci: bump plugin to v0.20.1\r\n* core: Bump Go version to 1.25.5\r\n* packaging: Container images are now exported using a compressed OCI image layout.\r\n* packaging: UBI container images are now built on the UBI 10 minimal image.\r\n* secrets/azure: Update plugin to v0.25.1+ent. Improves retry handling during Azure application and service principal creation to reduce transient failures.\r\n* storage: Upgrade aerospike client library to v8.\r\n\r\nIMPROVEMENTS:\r\n\r\n* core: check rotation manager queue every 5 seconds instead of 10 seconds to improve responsiveness\r\n* go: update to golang/x/crypto to v0.45.0 to resolve GHSA-f6x5-jh6r-wrfv, GHSA-j5w8-q4qc-rx2x, GO-2025-4134 and GO-2025-4135.\r\n* rotation: Ensure rotations for shared paths only execute on the Primary cluster's active node. Ensure rotations for local paths execute on the cluster-local active node.\r\n* sdk/rotation: Prevent rotation attempts on read-only storage.\r\n* secrets-sync (enterprise): Added support for a boolean force_delete flag (default: false). When set to true, this flag allows deletion of a destination even if its associations cannot be unsynced. This option should be used only as a last-resort deletion mechanism, as any secrets already synced to the external provider will remain orphaned and require manual cleanup.\r\n* secrets/pki: Avoid loading issuer information multiple times per leaf certificate signing.\r\n\r\nBUG FIXES:\r\n\r\n* core/activitylog (enterprise): Resolve a stability issue where Vault Enterprise could encounter a panic during month-end billing activity rollover.\r\n* http: skip JSON limit parsing on cluster listener.\r\n* quotas: Vault now protects plugins with ResolveRole operations from panicking on quota creation.\r\n* replication (enterprise): fix rare panic due to race when enabling a secondary with Consul storage.\r\n* rotation: Fix a bug where a performance secondary would panic if a write was made to a local mount.\r\n* secret-sync (enterprise): Improved unsync error handling by treating cases where the destination no longer exists as successful.\r\n* secrets-sync (enterprise): Corrected a bug where the deletion of the latest KV-V2 secret version caused the associated external secret to be deleted entirely. The sync job now implements a version fallback mechanism to find and sync the highest available active version, ensuring continuity and preventing the unintended deletion of the external secret resource.\r\n* secrets-sync (enterprise): Fix issue where secrets were not properly un-synced after destination config changes.\r\n* secrets-sync (enterprise): Fix issue where sync store deletion could be attempted when sync is disabled.\r\n* ui/pki: Fix handling of values that contain commas in list fields like `crl_distribution_points`.","publishedAt":"2026-01-07T18:09:58.000Z","fetchedAt":"2026-04-08T00:01:01.400Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.21.2","media":[],"coverageCount":0},{"id":"rel_TNl5hZsbyFvA08_iOLaU_","version":"v1.21.1","type":"feature","title":"v1.21.1","summary":"## 1.21.1\r\n### November 20, 2025\r\n\r\nSECURITY:\r\n\r\n* auth/aws: fix an issue where a user may be able to bypass authentication to Vault due to incorrect ...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.21.1\r\n### November 20, 2025\r\n\r\nSECURITY:\r\n\r\n* auth/aws: fix an issue where a user may be able to bypass authentication to Vault due to incorrect caching of the AWS client\r\n* ui: disable scarf analytics for ui builds\r\n\r\nCHANGES:\r\n\r\n* auth/kubernetes: Update plugin to [v0.23.1](https://github.com/hashicorp/vault-plugin-auth-kubernetes/releases/tag/v0.23.1)\r\n* auth/saml: Update plugin to [v0.7.0](https://github.com/hashicorp/vault-plugin-auth-saml/releases/tag/v0.7.0)\r\n* auth/saml: Update plugin to v0.7.1, which adds the environment variable VAULT_SAML_DENY_INTERNAL_URLS to allow prevention of idp_metadata_url, idp_sso_url, or acs_urls fields from containing URLs that resolve to internal IP addresses\r\n* core: Bump Go version to 1.25.4\r\n* secrets/azure: Update plugin to [v0.25.0+ent](https://github.com/hashicorp/vault-plugin-secrets-azure/releases/tag/v0.25.0+ent)\r\n* secrets/pki: sign-verbatim endpoints no longer ignore basic constraints extension in CSRs, using them in generated certificates if isCA=false or returning an error if isCA=true\r\n\r\nIMPROVEMENTS:\r\n\r\n* Update github.com/dvsekhvalnov/jose2go to fix security vulnerability CVE-2025-63811.\r\n* api: Added sudo-permissioned `sys/reporting/scan` endpoint which will output a set of files containing information about Vault state to the location specified by the `reporting_scan_directory` config item.\r\n* auth/ldap: Require non-empty passwords on login command to prevent unauthenticated access to Vault.\r\n* core/metrics: Reading and listing from a snapshot are now tracked via the `vault.route.read-snapshot.{mount_point}` and `vault.route.list-snapshot.{mount_point}` metrics.\r\n* license utilization reporting (enterprise): Add metrics for the number of issued PKI certificates.\r\n* policies: add warning about list comparison when using allowed_parameters or denied_parameters\r\n* secret-sync: add parallelization support to sync and unsync operations for secret-key granularity associations\r\n* secrets/pki: Include the certificate's AuthorityKeyID in response fields for API endpoints that issue, sign, or fetch certs.\r\n* sys (enterprise): Add sys/billing/certificates API endpoint to retrieve the number of issued PKI certificates.\r\n* ui/activity (enterprise): Add clarifying text to explain the \"Initial Usage\" column will only have timestamps for clients initially used after upgrading to version 1.21\r\n* ui/activity (enterprise): Allow manual querying of client usage if there is a problem retrieving the license start time.\r\n* ui/activity (enterprise): Reduce requests to the activity export API by only fetching new data when the dashboard initially loads or is manually refreshed.\r\n* ui/activity (enterprise): Support filtering months dropdown by ISO timestamp or display value.\r\n* ui/activity: Display total instead of new monthly clients for HCP managed clusters\r\n* ui/pki: Adds support to configure `server_flag`, `client_flag`, `code_signing_flag`, and `email_protection_flag` parameters for creating/updating a role.\r\n\r\nBUG FIXES:\r\n\r\n* activity (enterprise): sys/internal/counters/activity outputs the correct mount type when called from a non root namespace\r\n* auth/approle (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth/aws (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth/cert (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth/github (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth/ldap (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth/okta (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth/radius (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth/scep (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth/userpass (enterprise): Role parameter `alias_metadata` now populates alias custom metadata field instead of alias metadata.\r\n* auth: fixed panic when supplying integer as a lease_id in renewal.\r\n* core/rotation: avoid shifting timezones by ignoring cron.SpecSchedule\r\n* core: interpret all new rotation manager rotation_schedules as UTC to avoid inadvertent use of tz-local\r\n* secrets/azure: Ensure proper installation of the Azure enterprise secrets plugin.\r\n* secrets/pki: Return error when issuing/signing certs whose NotAfter is before NotBefore or whose validity period isn't contained by the CA's.\r\n* ui (enterprise): Fix KV v2 not displaying secrets in namespaces.\r\n* ui (enterprise): Fixes login form so input renders correctly when token is a preferred login method for a namespace.\r\n* ui/pki: Fixes certificate parsing of the `key_usage` extension so details accurately reflect certificate values.\r\n* ui/pki: Fixes creating and updating a role so `basic_constraints_valid_for_non_ca` is correctly set.\r\n* ui: Fix KV v2 metadata list request failing for policies without a trailing slash in the path.\r\n* ui: Resolved a regression that prevented users with create and update permissions on KV v1 secrets from opening the edit view. The UI now correctly recognizes these capabilities and allows editing without requiring full read access.\r\n* ui: Update LDAP accounts checked-in table to display hierarchical LDAP libraries\r\n* ui: Update LDAP library count to reflect the total number of nodes instead of number of directories\r\n","publishedAt":"2025-11-19T17:36:49.000Z","fetchedAt":"2026-04-08T00:01:01.400Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.21.1","media":[],"coverageCount":0},{"id":"rel_RaRZtu_RhdZEdx0vECUBr","version":"v1.21.0","type":"feature","title":"v1.21.0","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2025-10-22T20:29:23.000Z","fetchedAt":"2026-04-08T00:01:01.698Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.21.0","media":[],"coverageCount":0},{"id":"rel_ynZ9fHu8Zp98135Ohh9Ax","version":"v1.20.4","type":"feature","title":"v1.20.4","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2025-09-24T20:43:32.000Z","fetchedAt":"2026-04-08T00:01:01.698Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.20.4","media":[],"coverageCount":0},{"id":"rel_0vj4NKUOmpw56UdDAo5Ia","version":"v1.20.3","type":"feature","title":"v1.20.3","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2025-08-28T18:21:23.000Z","fetchedAt":"2026-04-08T00:01:01.698Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.20.3","media":[],"coverageCount":0},{"id":"rel_eonIvvouSgk-IbgJoklre","version":"v1.20.2","type":"feature","title":"v1.20.2","summary":"### August 06, 2025\r\n\r\nSECURITY:\r\n\r\n* auth/ldap: fix MFA/TOTP enforcement bypass when username_as_alias is enabled [[GH-31427](https://github.com/hash...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"### August 06, 2025\r\n\r\nSECURITY:\r\n\r\n* auth/ldap: fix MFA/TOTP enforcement bypass when username_as_alias is enabled [[GH-31427](https://github.com/hashicorp/vault/pull/31427),[HCSEC-2025-20](https://discuss.hashicorp.com/t/hcsec-2025-20-vault-ldap-mfa-enforcement-bypass-when-using-username-as-alias/76092)].\r\n\r\nBUG FIXES:\r\n\r\n* agent/template: Fixed issue where templates would not render correctly if namespaces was provided by config, and the namespace and mount path of the secret were the same. [[GH-31392](https://github.com/hashicorp/vault/pull/31392)]\r\n* identity/mfa: revert cache entry change from #31217 and document cache entry values [[GH-31421](https://github.com/hashicorp/vault/pull/31421)]","publishedAt":"2025-08-06T04:09:48.000Z","fetchedAt":"2026-04-08T00:01:01.698Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.20.2","media":[],"coverageCount":0},{"id":"rel_wOZB-xidFl6SRtCUtGzTL","version":"v1.20.1","type":"feature","title":"v1.20.1","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2025-07-24T20:10:34.000Z","fetchedAt":"2026-04-08T00:01:01.958Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.20.1","media":[],"coverageCount":0},{"id":"rel_7Z30Z88xD5OiPZ-iez9wX","version":"v1.20.0","type":"feature","title":"v1.20.0","summary":"## 1.20.0\r\n### June 25, 2025\r\n\r\nSECURITY:\r\n\r\n* core: require a nonce when cancelling a rekey operation that was initiated within the last 10 minutes. ...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.20.0\r\n### June 25, 2025\r\n\r\nSECURITY:\r\n\r\n* core: require a nonce when cancelling a rekey operation that was initiated within the last 10 minutes. [[GH-30794](https://github.com/hashicorp/vault/pull/30794)]\r\n\r\nCHANGES:\r\n\r\n* UI: remove outdated and unneeded js string extensions [[GH-29834](https://github.com/hashicorp/vault/pull/29834)]\r\n* activity (enterprise): The sys/internal/counters/activity endpoint will return actual values for new clients in the current month.\r\n* activity (enterprise): provided values for `start_time` and `end_time` in `sys/internal/counters/activity` are aligned to the corresponding billing period.\r\n* activity: provided value for `end_time` in `sys/internal/counters/activity` is now capped at the end of the last completed month. [[GH-30164](https://github.com/hashicorp/vault/pull/30164)]\r\n* api: Update the default API client to check for the `Retry-After` header and, if it exists, wait for the specified duration before retrying the request. [[GH-30887](https://github.com/hashicorp/vault/pull/30887)]\r\n* auth/alicloud: Update plugin to v0.21.0 [[GH-30810](https://github.com/hashicorp/vault/pull/30810)]\r\n* auth/azure: Update plugin to v0.20.2. Login requires `resource_group_name`, `vm_name`, and `vmss_name` to match token claims [[GH-30052](https://github.com/hashicorp/vault/pull/30052)]\r\n* auth/azure: Update plugin to v0.20.3 [[GH-30082](https://github.com/hashicorp/vault/pull/30082)]\r\n* auth/azure: Update plugin to v0.20.4 [[GH-30543](https://github.com/hashicorp/vault/pull/30543)]\r\n* auth/azure: Update plugin to v0.21.0 [[GH-30872](https://github.com/hashicorp/vault/pull/30872)]\r\n* auth/azure: Update plugin to v0.21.1 [[GH-31010](https://github.com/hashicorp/vault/pull/31010)]\r\n* auth/cf: Update plugin to v0.20.1 [[GH-30583](https://github.com/hashicorp/vault/pull/30583)]\r\n* auth/cf: Update plugin to v0.21.0 [[GH-30842](https://github.com/hashicorp/vault/pull/30842)]\r\n* auth/gcp: Update plugin to v0.20.2 [[GH-30081](https://github.com/hashicorp/vault/pull/30081)]\r\n* auth/jwt: Update plugin to v0.23.2 [[GH-30431](https://github.com/hashicorp/vault/pull/30431)]\r\n* auth/jwt: Update plugin to v0.24.1 [[GH-30876](https://github.com/hashicorp/vault/pull/30876)]\r\n* auth/kerberos: Update plugin to v0.15.0 [[GH-30845](https://github.com/hashicorp/vault/pull/30845)]\r\n* auth/kubernetes: Update plugin to v0.22.1 [[GH-30910](https://github.com/hashicorp/vault/pull/30910)]\r\n* auth/oci: Update plugin to v0.19.0 [[GH-30841](https://github.com/hashicorp/vault/pull/30841)]\r\n* auth/saml: Update plugin to v0.6.0\r\n* core: Bump Go version to 1.24.4.\r\n* core: Verify that the client IP address extracted from an X-Forwarded-For header is a valid IPv4 or IPv6 address [[GH-29774](https://github.com/hashicorp/vault/pull/29774)]\r\n* database/couchbase: Update plugin to v0.14.0 [[GH-30836](https://github.com/hashicorp/vault/pull/30836)]\r\n* database/elasticsearch: Update plugin to v0.18.0 [[GH-30796](https://github.com/hashicorp/vault/pull/30796)]\r\n* database/mongodbatlas: Update plugin to v0.15.0 [[GH-30856](https://github.com/hashicorp/vault/pull/30856)]\r\n* database/redis-elasticache: Update plugin to v0.7.0 [[GH-30785](https://github.com/hashicorp/vault/pull/30785)]\r\n* database/redis: Update plugin to v0.6.0 [[GH-30797](https://github.com/hashicorp/vault/pull/30797)]\r\n* database/snowflake: Update plugin to v0.14.0 [[GH-30748](https://github.com/hashicorp/vault/pull/30748)]\r\n* database/snowflake: Update plugin to v0.14.1 [[GH-30868](https://github.com/hashicorp/vault/pull/30868)]\r\n* logical/system: add ent stub for plugin catalog handling [[GH-30890](https://github.com/hashicorp/vault/pull/30890)]\r\n* quotas/rate-limit: Round up the `Retry-After` value to the nearest second when calculating the retry delay. [[GH-30887](https://github.com/hashicorp/vault/pull/30887)]\r\n* secrets/ad: Update plugin to v0.21.0 [[GH-30819](https://github.com/hashicorp/vault/pull/30819)]\r\n* secrets/alicloud: Update plugin to v0.20.0 [[GH-30809](https://github.com/hashicorp/vault/pull/30809)]\r\n* secrets/azure: Update plugin to v0.21.2 [[GH-30037](https://github.com/hashicorp/vault/pull/30037)]\r\n* secrets/azure: Update plugin to v0.21.3 [[GH-30083](https://github.com/hashicorp/vault/pull/30083)]\r\n* secrets/azure: Update plugin to v0.22.0 [[GH-30832](https://github.com/hashicorp/vault/pull/30832)]\r\n* secrets/gcp: Update plugin to v0.21.2 [[GH-29970](https://github.com/hashicorp/vault/pull/29970)]\r\n* secrets/gcp: Update plugin to v0.21.3 [[GH-30080](https://github.com/hashicorp/vault/pull/30080)]\r\n* secrets/gcp: Update plugin to v0.22.0 [[GH-30846](https://github.com/hashicorp/vault/pull/30846)]\r\n* secrets/gcpkms: Update plugin to v0.21.0 [[GH-30835](https://github.com/hashicorp/vault/pull/30835)]\r\n* secrets/kubernetes: Update plugin to v0.11.0 [[GH-30855](https://github.com/hashicorp/vault/pull/30855)]\r\n* secrets/kv: Update plugin to v0.24.0 [[GH-30826](https://github.com/hashicorp/vault/pull/30826)]\r\n* secrets/mongodbatlas: Update plugin to v0.15.0 [[GH-30860](https://github.com/hashicorp/vault/pull/30860)]\r\n* secrets/openldap: Update plugin to v0.15.2 [[GH-30079](https://github.com/hashicorp/vault/pull/30079)]\r\n* secrets/openldap: Update plugin to v0.15.4 [[GH-30279](https://github.com/hashicorp/vault/pull/30279)]\r\n* secrets/openldap: Update plugin to v0.16.0 [[GH-30844](https://github.com/hashicorp/vault/pull/30844)]\r\n* secrets/terraform: Update plugin to v0.12.0 [[GH-30905](https://github.com/hashicorp/vault/pull/30905)]\r\n* server: disable_mlock configuration option is now required for integrated storage and no longer has a default. If you are using the default value with integrated storage, you must now explicitly set disable_mlock to true or false or Vault server will fail to start. [[GH-29974](https://github.com/hashicorp/vault/pull/29974)]\r\n* ui/activity: Replaces mount and namespace attribution charts with a table to allow sorting \r\nclient count data by `namespace`, `mount_path`, `mount_type` or number of clients for \r\na selected month. [[GH-30678](https://github.com/hashicorp/vault/pull/30678)]\r\n* ui: Client count side nav link 'Vault Usage Metrics' renamed to 'Client Usage' [[GH-30765](https://github.com/hashicorp/vault/pull/30765)]\r\n* ui: Client counting \"running total\" charts now reflect new clients only [[GH-30506](https://github.com/hashicorp/vault/pull/30506)]\r\n* ui: Removed `FormError` component (not used) [[GH-34699](https://github.com/hashicorp/vault/pull/34699)]\r\n* ui: Selecting a different method in the login form no longer updates the `/vault/auth?with=` query parameter [[GH-30500](https://github.com/hashicorp/vault/pull/30500)]\r\n* ui: `/vault/auth?with=` query parameter now exclusively refers to the auth mount path and renders a simplified form [[GH-30500](https://github.com/hashicorp/vault/pull/30500)]\r\n\r\nFEATURES:\r\n\r\n* **Auto Irrevocable Lease Removal (Enterprise)**: Add the Vault Enterprise configuration param, `remove_irrevocable_lease_after`. When set to a non-zero value, this will automatically delete irrevocable leases after the configured duration exceeds the lease's expire time. The minimum duration allowed for this field is two days. [[GH-30703](https://github.com/hashicorp/vault/pull/30703)]\r\n* **Development Cluster Configuration (Enterprise)**: Added `development_cluster` as a field to Vault's utilization reports.\r\nThe field is configurable via HCL and indicates whether the cluster is being used in a development environment, defaults to false if not set. [[GH-30659](https://github.com/hashicorp/vault/pull/30659)]\r\n* **Entity-based and collective rate limit quotas (Enterprise)**: Add new `group_by` field to the rate limit quota API to support different grouping modes.\r\n* **Login form customization (Enterprise)**: Adds support to choose a default and/or backup auth methods for the web UI login form to streamline the web UI login experience. [[GH-30700](https://github.com/hashicorp/vault/pull/30700)]\r\n* **Plugin Downloads**: Support automatically downloading official HashiCorp secret and auth plugins from releases.hashicorp.com (beta)\r\n* **SSH Key Signing Improvements (Enterprise)**: Add support for using managed keys to sign SSH keys in the SSH secrets engine.\r\n* **Secret Recovery from Snapshot (Enterprise)**: Adds a framework to load an integrated storage \r\nsnapshot into Vault and read, list, and recover KV v1 and cubbyhole secrets from the snapshot. [[GH-30739](https://github.com/hashicorp/vault/pull/30739)]\r\n* **UI Secrets Engines**: TOTP secrets engine is now supported. [[GH-29751](https://github.com/hashicorp/vault/pull/29751)]\r\n* **UI Telemetry**: Add Posthog for UI telemetry tracking on Vault Dedicated managed clusters [[GH-30425](https://github.com/hashicorp/vault/pull/30425)]\r\n* **Vault Namespace Picker**: Updating the Vault Namespace Picker to enable search functionality, allow direct navigation to nested namespaces and improve accessibility. [[GH-30490](https://github.com/hashicorp/vault/pull/30490)]\r\n* **Vault PKI SCEP Server (Enterprise)**: Support for the Simple Certificate Enrollment Protocol (SCEP) has been added to the Vault PKI Plugin. This allows standard SCEP clients to request certificates from a Vault server with no knowledge of Vault APIs.\r\n\r\nIMPROVEMENTS:\r\n\r\n* activity (enterprise): Added vault.client.billing_period.activity telemetry metric to emit information about the total number of distinct clients used in the current billing period.\r\n* activity: mount_type was added to the API response of sys/internal/counters/activity [[GH-30071](https://github.com/hashicorp/vault/pull/30071)]\r\n* activity: mount_type was added to the API response of sys/internal/counters/activity\r\n* api (enterprise): Added a new API, `/sys/utilization-report`, giving a snapshot overview of Vault's utilization at a high level.\r\n* api/client: Add Cert auth method support. This allows the client to authenticate using a client certificate. [[GH-29546](https://github.com/hashicorp/vault/pull/29546)]\r\n* core (enterprise): Updated code and documentation to support FIPS 140-3 compliant algorithms.\r\n* core (enterprise): allow a root token to relock a namespace locked by the Namespace API Lock feature.\r\n* core (enterprise): report errors from the underlying seal when getting entropy.\r\n* core (enterprise): update to FIPS 140-3 cryptographic module in the FIPS builds.\r\n* core/metrics: added a new telemetry metric, `vault.core.response_status_code`, with two labels, `code`, and `type`, detailing the status codes of all responses to requests that Vault handles. [[GH-30354](https://github.com/hashicorp/vault/pull/30354)]\r\n* core: Improve memory use of path management for namespaces, auth methods, and secrets engines. Now Vault should handle larger numbers of namespaces and multiple instances of the same secrets engine or auth method more efficiently. [[GH-31022](https://github.com/hashicorp/vault/pull/31022)]\r\n* core: Updated code and documentation to support FIPS 140-3 compliant algorithms. [[GH-30576](https://github.com/hashicorp/vault/pull/30576)]\r\n* core: support for X25519MLKEM768 (post quantum key agreement) in the Go TLS stack. [[GH-30603](https://github.com/hashicorp/vault/pull/30603)]\r\n* events: Add `vault_index` to an event's metadata if the metadata contains `modified=true`, to support client consistency controls when reading from Vault in response to an event where storage was modified. [[GH-30725](https://github.com/hashicorp/vault/pull/30725)]\r\n* physical/postgres: Adds support to authenticate with the PostgreSQL Backend server with cloud based identities (AWS IAM, Azure MSI and GCP IAM) [[GH-30681](https://github.com/hashicorp/vault/pull/30681)]\r\n* plugins: Support registration of CE plugins with extracted artifact directory. [[GH-30673](https://github.com/hashicorp/vault/pull/30673)]\r\n* secrets/aws: Add LIST endpoint to the AWS secrets engine static roles. [[GH-29842](https://github.com/hashicorp/vault/pull/29842)]\r\n* secrets/pki: Add Delta (Freshest) CRL support to AIA information (both mount-level and issuer configured) [[GH-30319](https://github.com/hashicorp/vault/pull/30319)]\r\n* secrets/transit (enterprise): enable the use of 192-bit keys for AES CMAC\r\n* storage/mysql: Added support for getting mysql backend username and password from the environment variables `VAULT_MYSQL_USERNAME` and `VAULT_MYSQL_PASSWORD`. [[GH-30136](https://github.com/hashicorp/vault/pull/30136)]\r\n* storage/raft: Upgrade hashicorp/raft library to v1.7.3 which includes additional logging on the leader when opening and sending a snapshot to a follower. [[GH-29976](https://github.com/hashicorp/vault/pull/29976)]\r\n* transit: Exclude the partial wrapping key path from the transit/keys LIST operation. [[GH-30728](https://github.com/hashicorp/vault/pull/30728)]\r\n* ui (enterprise): Replace date selector in client count usage page with fixed start and end dates that align with billing periods in order to return more relevant client counting data. [[GH-30349](https://github.com/hashicorp/vault/pull/30349)]\r\n* ui/database: Adding input field for setting skip static role password rotation for database connection config, updating static role skip field to use toggle button [[GH-29820](https://github.com/hashicorp/vault/pull/29820)]\r\n* ui/database: Adding password input field for creating a static role [[GH-30275](https://github.com/hashicorp/vault/pull/30275)]\r\n* ui/database: Adding warning modal pop up when creating a static role that will be rotated immediately [[GH-30119](https://github.com/hashicorp/vault/pull/30119)]\r\n* ui/database: Glimmerizing and adding validations to role create [[GH-29754](https://github.com/hashicorp/vault/pull/29754)]\r\n* ui/database: Updating toggle buttons for skip_rotation_import to reverse polarity of values that get displayed versus whats sent to api [[GH-30055](https://github.com/hashicorp/vault/pull/30055)]\r\n* ui: Add 'Refresh list' button to the namespace list page. [[GH-30692](https://github.com/hashicorp/vault/pull/30692)]\r\n* ui: Enable search for a namespace on the namespace list page. [[GH-30680](https://github.com/hashicorp/vault/pull/30680)]\r\n* ui: Hide \"Other\" tab when mounts are configured with `listing_visibility=\"unauth\"`; all methods can be accessed via the \"Sign in with other methods\" link [[GH-30500](https://github.com/hashicorp/vault/pull/30500)]\r\n* ui: Improve accessibility of login form to meet a11y standards [[GH-30500](https://github.com/hashicorp/vault/pull/30500)]\r\n* ui: Replaces all instances of the deprecated event.keyCode with event.key [[GH-30493](https://github.com/hashicorp/vault/pull/30493)]\r\n* ui: Update date selector in client count usage page to disable current month selection for Vault clusters without a license. [[GH-30488](https://github.com/hashicorp/vault/pull/30488)]\r\n* ui: Use Hds::CodeBlock component to replace readonly JsonEditor instances [[GH-29720](https://github.com/hashicorp/vault/pull/29720)]\r\n* ui: adds key value pair string inputs as optional form for wrap tool [[GH-29677](https://github.com/hashicorp/vault/pull/29677)]\r\n* ui: remove ember-svg-jar dependency [[GH-30181](https://github.com/hashicorp/vault/pull/30181)]\r\n\r\nDEPRECATIONS:\r\n\r\n* api: Deprecated the `/sys/internal/counters/tokens` endpoint. Attempting to call this endpoint will return a 403 \"unsupported path\" exception. [[GH-30561](https://github.com/hashicorp/vault/pull/30561)]\r\n* core: deprecate duplicate attributes in HCL configuration files and policy definitions [[GH-30386](https://github.com/hashicorp/vault/pull/30386)]\r\n\r\nBUG FIXES:\r\n\r\n* api/tokenhelper: Exec token_helper without a shell [[GH-29653](https://github.com/hashicorp/vault/pull/29653)]\r\n* auth/aws: fix a panic when a performance standby node attempts to write/update config. [[GH-30039](https://github.com/hashicorp/vault/pull/30039)]\r\n* auth/ldap: Fix a bug that does not properly delete users and groups by first converting their names to lowercase when case senstivity option is off. [[GH-29922](https://github.com/hashicorp/vault/pull/29922)]\r\n* auth/ldap: fix a panic when a performance standby node attempts to write/update config. [[GH-30039](https://github.com/hashicorp/vault/pull/30039)]\r\n* aws/secrets: Prevent vault from rejecting secret role configurations where no regions or endpoints are set [[GH-29996](https://github.com/hashicorp/vault/pull/29996)]\r\n* core (enterprise): add nil check before attempting to use Rotation Manager operations.\r\n* core (enterprise): fix a bug where plugin automated root rotations would stop after seal/unseal operations\r\n* core (enterprise): fix issue with errors being swallowed on failed HSM logins. \r\ncore/managed-keys (enterprise): fix RSA encryption/decryption with OAEP on managed keys.\r\n* core: Fix a bug that prevents certain loggers from writing to a log file. [[GH-29917](https://github.com/hashicorp/vault/pull/29917)]\r\n* core: Fix string contains check in Identity APIs to be case-insensitive. [[GH-31045](https://github.com/hashicorp/vault/pull/31045)]\r\n* core: Omit automatic version control information of the main module from compiled Vault binaries [[GH-30926](https://github.com/hashicorp/vault/pull/30926)]\r\n* database: Prevent static roles created in versions prior to 1.15.0 from rotating on backend restart. [[GH-30320](https://github.com/hashicorp/vault/pull/30320)]\r\n* database: no longer incorrectly add an \"unrecognized parameters\" warning for certain SQL database secrets config operations when another warning is returned [[GH-30327](https://github.com/hashicorp/vault/pull/30327)]\r\n* identity: Fix non-deterministic merge behavior when two entities have\r\nconflicting local aliases. [[GH-30390](https://github.com/hashicorp/vault/pull/30390)]\r\n* identity: reintroduce RPC functionality for group creates, allowing performance standbys to handle external group changes during login and token renewal [[GH-30069](https://github.com/hashicorp/vault/pull/30069)]\r\n* plugins (enterprise): Fix an issue where Enterprise plugins can't run on a standby node\r\nwhen it becomes active because standby nodes don't extract the artifact when the plugin\r\nis registered. Remove extracting from Vault and require the operator to place\r\nthe extracted artifact in the plugin directory before registration.\r\n* plugins (enterprise): Fix plugin registration with artifact when a binary for the same plugin is already present in the plugin directory.\r\n* plugins: plugin registration should honor the `plugin_tmpdir` config [[GH-29978](https://github.com/hashicorp/vault/pull/29978)]\r\n* plugins: plugin registration should honor the `plugin_tmpdir` config\r\n* raft/retry_join: Fix decoding `auto_join` configurations that include escape characters [[GH-29874](https://github.com/hashicorp/vault/pull/29874)]\r\n* secrets/aws: fix a bug where environment and shared credential providers were overriding the WIF configuration [[GH-29982](https://github.com/hashicorp/vault/pull/29982)]\r\n* secrets/aws: fix a case where GovCloud wasn't taken into account; fix a case where the region setting wasn't respected [[GH-30312](https://github.com/hashicorp/vault/pull/30312)]\r\n* secrets/aws: fix a panic when a performance standby node attempts to write/update config. [[GH-30039](https://github.com/hashicorp/vault/pull/30039)]\r\n* secrets/database: Fix a bug where a global database plugin reload exits if any of the database connections are not available [[GH-29519](https://github.com/hashicorp/vault/pull/29519)]\r\n* secrets/database: Treat all rotation_schedule values as UTC to ensure consistent behavior. [[GH-30606](https://github.com/hashicorp/vault/pull/30606)]\r\n* secrets/db: fix a panic when a performance standby node attempts to write/update config. [[GH-30039](https://github.com/hashicorp/vault/pull/30039)]\r\n* secrets/openldap: Prevent static role rotation on upgrade when `NextVaultRotation` is nil.\r\nFixes an issue where static roles were unexpectedly rotated after upgrade due to a missing `NextVaultRotation` value. \r\nNow sets it to either `LastVaultRotation + RotationPeriod` or `now + RotationPeriod`. [[GH-30265](https://github.com/hashicorp/vault/pull/30265)]\r\n* secrets/pki (enterprise): Address a parsing bug that rejected CMPv2 requests containing a validity field.\r\n* secrets/pki: Fix a bug that prevents enabling automatic tidying of the CMPv2 nonce store. [[GH-29852](https://github.com/hashicorp/vault/pull/29852)]\r\n* secrets/pki: fix a bug where key_usage was ignored when generating root certificates, and signing certain\r\nintermediate certificates. [[GH-30034](https://github.com/hashicorp/vault/pull/30034)]\r\n* secrets/transit (enterprise): ensure verify endpoint always returns valid field in batch_results with CMAC\r\n* secrets/transit (enterprise): fixed encryption/decryption with RSA against PKCS#11 managed keys\r\n* secrets/transit: ensure verify endpoint always returns valid field in batch_results with HMAC [[GH-30852](https://github.com/hashicorp/vault/pull/30852)]\r\n* secrets/transit: fix a panic when rotating on a managed key returns an error [[GH-30214](https://github.com/hashicorp/vault/pull/30214)]\r\n* ui/database: Added input field for setting 'skip_import_rotation' when creating a static role [[GH-29633](https://github.com/hashicorp/vault/pull/29633)]\r\n* ui/kmip: Fixes KMIP credentials view and displays `private_key` after generating [[GH-30778](https://github.com/hashicorp/vault/pull/30778)]\r\n* ui: Automatically refresh namespace list inside the namespace picker after creating or deleting a namespace in the UI. [[GH-30737](https://github.com/hashicorp/vault/pull/30737)]\r\n* ui: Fix broken link to Hashicorp Vault developer site in the Web REPL help. [[GH-30670](https://github.com/hashicorp/vault/pull/30670)]\r\n* ui: Fix initial setting of form toggle inputs for parameters nested within the `config` block [[GH-30960](https://github.com/hashicorp/vault/pull/30960)]\r\n* ui: Fix refresh namespace list after deleting a namespace. [[GH-30680](https://github.com/hashicorp/vault/pull/30680)]\r\n* ui: MFA methods now display the namespace path instead of the namespace id. [[GH-29588](https://github.com/hashicorp/vault/pull/29588)]\r\n* ui: Redirect users authenticating with Vault as an OIDC provider to log in again when token expires. [[GH-30838](https://github.com/hashicorp/vault/pull/30838)]\r\n","publishedAt":"2025-06-25T13:57:41.000Z","fetchedAt":"2026-04-08T00:01:01.958Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.20.0","media":[],"coverageCount":0},{"id":"rel_R7FgVtf3gbIGvMEWcXYAH","version":"v1.19.5","type":"feature","title":"v1.19.5","summary":"## 1.19.5\r\n### May 30, 2025\r\n\r\n**Enterprise LTS:** Vault Enterprise 1.19 is a [Long-Term Support (LTS)](https://developer.hashicorp.com/vault/docs/ent...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.19.5\r\n### May 30, 2025\r\n\r\n**Enterprise LTS:** Vault Enterprise 1.19 is a [Long-Term Support (LTS)](https://developer.hashicorp.com/vault/docs/enterprise/lts) release.\r\n\r\nCHANGES:\r\n\r\n* database/snowflake: Update plugin to v0.13.1 [[GH-30775](https://github.com/hashicorp/vault/pull/30775)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* plugins: Support registration of CE plugins with extracted artifact directory. [[GH-30673](https://github.com/hashicorp/vault/pull/30673)]\r\n\r\nBUG FIXES:\r\n\r\n* ui: Fix broken link to Hashicorp Vault developer site in the Web REPL help. [[GH-30670](https://github.com/hashicorp/vault/pull/30670)]","publishedAt":"2025-05-29T22:59:58.000Z","fetchedAt":"2026-04-08T00:01:01.958Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.19.5","media":[],"coverageCount":0},{"id":"rel_h03K4pSq-_E9IU0z_6_a7","version":"v1.19.4","type":"feature","title":"v1.19.4","summary":"## 1.19.4\r\n### May 16, 2025\r\n\r\nCHANGES:\r\n\r\n* Update vault-plugin-auth-cf to v0.20.1 [[GH-30586](https://github.com/hashicorp/vault/pull/30586)]\r\n* aut...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.19.4\r\n### May 16, 2025\r\n\r\nCHANGES:\r\n\r\n* Update vault-plugin-auth-cf to v0.20.1 [[GH-30586](https://github.com/hashicorp/vault/pull/30586)]\r\n* auth/azure: Update plugin to v0.20.4 [[GH-30543](https://github.com/hashicorp/vault/pull/30543)]\r\n* core: Bump Go version to 1.24.3.\r\n\r\nIMPROVEMENTS:\r\n\r\n* Namespaces (enterprise): allow a root token to relock a namespace\r\n* core (enterprise): update to FIPS 140-3 cryptographic module in the FIPS builds.\r\n* core: Updated code and documentation to support FIPS 140-3 compliant algorithms. [[GH-30576](https://github.com/hashicorp/vault/pull/30576)]\r\n* core: support for X25519MLKEM768 (post quantum key agreement) in the Go TLS stack. [[GH-30603](https://github.com/hashicorp/vault/pull/30603)]\r\n* ui: Replaces all instances of the deprecated event.keyCode with event.key [[GH-30493](https://github.com/hashicorp/vault/pull/30493)]\r\n\r\nBUG FIXES:\r\n\r\n* core (enterprise): fix a bug where plugin automated root rotations would stop after seal/unseal operations\r\n* plugins (enterprise): Fix an issue where Enterprise plugins can't run on a standby node\r\nwhen it becomes active because standby nodes don't extract the artifact when the plugin\r\nis registered. Remove extracting from Vault and require the operator to place\r\nthe extracted artifact in the plugin directory before registration.","publishedAt":"2025-05-16T17:52:45.000Z","fetchedAt":"2026-04-08T00:01:02.304Z","url":"https://github.com/hashicorp/vault/releases/tag/v1.19.4","media":[],"coverageCount":0}],"pagination":{"nextCursor":"2025-05-16T17:52:45.000Z|2026-04-08T00:01:02.304Z|rel_h03K4pSq-_E9IU0z_6_a7","limit":20},"summaries":{"rolling":null,"monthly":[]}}