Vault
$
npx @buildinternet/releases get vault-releasesMon
Wed
Fri
OctNovDecJanFebMarAprMayJunJulAugSepOct
LessMore
Releases5Avg2/moVersionsv2.0.4 to v2.1.2
Last Checked
10h ago
npx @buildinternet/releases get vault-releasesSECURITY:
CHANGES:
too many concurrent raft retry joins in progress).IMPROVEMENTS:
allowed_ipv4_cidrs to source_aws and source_azure Secrets Import blocks to allow private CIDR exemptions for SSRF-safe connectivity.BUG FIXES:
vault recover without a path.auth/token/lookup and auth/token/lookup-self returned 403 for JWT tokens in a non-root namespace.vault secrets move (and vault auth move) incorrectly placing a mount in the root namespace when the destination path has a leading slash.iss claim had cosmetic differences (e.g. different casing or trailing slash) compared to the issuer stored in the resource server profile.vault plugin reload -mounts command when run in the root namespaceLIST /v1/sys/sync/associations intermittently returning zero associations/secrets by forwarding the request to the active node instead of allowing it to be served locally by a performance standby or performance secondary.SECURITY:
CHANGES:
sys/activation-flags/oauth-resource-server/activate endpoint.FEATURES:
IMPROVEMENTS:
dompurify from 3.4.6 to 3.4.13.delete-engine to confirm, displays the engine name, secret count (KV engines only), and a list of what will be permanently deleted. ConfirmModal has now been updated to include a optional type-to-confirm.BUG FIXES:
ca_chain field was always empty in templates due to incorrect type handling of array responsescollectOperatorImportMetrics when router.Route returns a nil response with no error during KVv2 metadata reads on performance secondary nodes. This condition occurs during the WAL-stream partial-sync phase of an initial join.vault operator migrate -start command when migrating to raft integrated storage.optional_authorization_details was incorrectly ignored for delegated (OBO) workflows when the subject has no agent registration, resulting in RAR not being mandatory in those requests.-version now auto-selects it when only one version exists, or returns an error listing available versions, instead of a silent 404.GET requests with ?list=true were incorrectly cached and served stale.rotation_period and rotation_schedule fields to be set simultaneously. The SDK now explicitly empties the opposing field to guarantee mutual-exclusion.service_registration stanza.token_reviewer_jwt — the wrong OpenAPI schema key (KubernetesConfigureRequest) was used instead of KubernetesConfigureAuthRequest, causing the JWT field to be omitted from the form and API payload on save.?namespace=root in the URLBREAKING CHANGES:
SECURITY:
denied_parameters constraint on the policies request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the policies parameter to lowercase before evaluating allowed_parameters/denied_parameters constraints.identity/entity/merge endpoint now rejects requests that involve any SCIM-managed entity, preventing privileged operators from bypassing SCIM ownership guardrails to transfer aliases, group memberships, or policies across SCIM boundaries.CHANGES:
FEATURES:
IMPROVEMENTS:
sys/config/oauth-resource-server/id/:config_id to read oauth resource server profiles by config_idtyp validation more permissive for tokens from IdPs such as Okta by allowing a missing typ header, while restricting present typ values to at+jwt, application/at+jwt, and JWT.deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false.deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false.VAULT_EVENT_NOTIFICATIONS_BOUNDED_QUEUE_SIZE environment variable to configure bounded event queues for event notification subscribers. Set to a positive integer (e.g., 16) to enable buffered channels of that size (maximum 1000). This prevents resource exhaustion in deployments with high subscriber counts, but comes at the cost of the potential for subscribers to miss events. Defaults to 0 (unbuffered) for backward compatibility.GET /scim/v2/Users and GET /scim/v2/Groups endpoints per RFC 7644. Supported filters: userName eq, externalId eq, active eq, and meta.lastModified gt/ge/lt/le for Users; displayName eq and meta.lastModified gt/ge/lt/le for Groups. Unsupported filter expressions return HTTP 400. ServiceProviderConfig now advertises filter.supported: true.allowed_parameters, denied_parameters, and required_parameters inside authorization_details.{{identity.entity.id}}) in Rich Authorization Requests (RAR).groups field listing the direct group memberships managed by the requesting SCIM client, per RFC 7643.tmp from 0.2.6 to 0.2.7.ws from 8.20.1 to 8.21.0.BUG FIXES:
sys/storage/raft/snapshot-load or read/delete requests to sys/storage/raft/snapshot-load/{id}. If possible, handle these requests on the performance standby, otherwise forward the requests to the active node.sys/billing/overview to return a 500 error with "lz4: bad magic number". The storage encoding now uses plain decimal strings consistent with other billing metrics, avoiding misidentification as lz4-compressed data.?list=true, potentially changing the result of the request.authorization_details array like an absent claim when authorization details are optional. Previously, tokens containing an empty array were rejected with RAR_NO_MATCH instead of continuing through normal identity and policy authorization.tls_disable when displaying TLS status in the Cluster Configuration widget.SECURITY:
CHANGES:
path "kv/*" { deny } could be bypassed for LIST kv/private/ if a broader allow path "kv/*" also existed. Policies relying on the previous (incorrect) behavior may now be denied././, /../, or //) to a cleaned path, instead of rejecting these requestsFEATURES:
IMPROVEMENTS:
sys/billing/config endpoint to allow configuration of billing data retention (min 13 months, max 6 years).path value in patch operationsBUG FIXES:
performance_multiplier values less than or equal to zeroBREAKING CHANGES:
cap_ipc_lock capability on vault at build time to allow running Vault in common container runtimes. Vault in containers will no longer be able to call mlock() to lock memory. Operators should set disable_mlock = true in Vault's configuration. Runtime operators are advised to disable swapping to guarantee data safety.CHANGES:
BUG FIXES:
BREAKING CHANGES:
IPC_LOCK capabilities when running the vault container.SECURITY:
path and file_path cannot be empty for requests to sys/audit/{path}CHANGES:
sudo capability to invoke the identity entity merge API endpoint (identity/entity/merge).FEATURES:
IMPROVEMENTS:
start_month and end_month parameters to /sys/billing/overview endpoint to allow querying billing data for specific time ranges.sys/billing/overview endpoint in admin namespace.sys/billing/overview are now rounded to 4 decimal places./sys/internal/billing/overview API endpoint now returns 37 months of historical consumption billing data by default./sys/internal/billing/overview API endpoint now always returns all metric types in the response, even when their values are zero. This ensures consistent response structure for easier client-side parsing.BUG FIXES:
sp_msloginmappings procedure with a granular metadata query. This allows the plugin to function with VIEW ANY DEFINITION instead of full sysadmin privileges.remove_roots_from_chain is true.