Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Vault 1.21.4: Sicherheitsupdates und Verbesserungen
Vault 1.21.4 aktualisiert Abhängigkeiten wegen Sicherheitslücken, hebt Go auf 1.25.7 an, entfernt das Massenlöschen von Secrets Engines in der UI und bringt Verbesserungen sowie Fehlerbehebungen, vor allem für Enterprise.
SECURITY:
- Upgrade
cloudflare/circlto v1.6.3 to resolve CVE-2026-1229 - Upgrade
filippo.io/edwards25519to v1.1.1 to resolve GO-2026-4503 - vault/sdk: Upgrade
cloudflare/circlto v1.6.3 to resolve CVE-2026-1229 - vault/sdk: Upgrade
go.opentelemetry.io/otel/sdkto v1.40.0 to resolve GO-2026-4394
CHANGES:
- core: Bump Go version to 1.25.7
- mfa/duo: Upgrade duo_api_golang client to 0.2.0 to include the new Duo certificate authorities
- ui: Remove ability to bulk delete secrets engines from the list view.
IMPROVEMENTS:
- core/seal: Enhance sys/seal-backend-status to provide more information about seal backends.
- secrets/kmip (Enterprise): Obey configured best_effort_wal_wait_duration when forwarding kmip requests.
- secrets/pki (enterprise): Return the POSTPKIOperation capability within SCEP GetCACaps endpoint for better legacy client support.
BUG FIXES:
- core (enterprise): Buffer the POST body on binary paths to allow re-reading on non-logical forwarding attempts. Addresses an issue for SCEP, EST and CMPv2 certificate issuances with slow replication of entities
- core/identity (enterprise): Fix excessive logging when updating existing aliases
- core/managed-keys (enterprise): client credentials should not be required when using Azure Managed Identities in managed keys.
- plugins (enterprise): Fix bug where requests to external plugins that modify storage weren't populating the X-Vault-Index response header. …