NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #54 by repository stars
Last release today
08 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 31 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
11517 releases · first in 2015
Nothing published for this version
Upgrade cloudflare/circl to v1.6.3 to resolve CVE-2026-1229
SECURITY:
cloudflare/circl to v1.6.3 to resolve CVE-2026-1229filippo.io/edwards25519 to v1.1.1 to resolve GO-2026-4503cloudflare/circl to v1.6.3 to resolve CVE-2026-1229go.opentelemetry.io/otel/sdk to v1.40.0 to resolve GO-2026-4394CHANGES:
IMPROVEMENTS:
BUG FIXES:
One column per quarter.
auth/cert: ensure that the certificate being renewed matches the certificate attached to the session.
SECURITY:
CHANGES:
FEATURES:
IMPROVEMENTS:
BUG FIXES:
?with=<path> query param correctly displays only the specified mount when multiple mounts of the same auth type are configured with listing_visibility="unauth"auth/oci: bump plugin to v0.20.1
CHANGES:
IMPROVEMENTS:
BUG FIXES:
crl_distribution_points.Update github.com/dvsekhvalnov/jose2go to fix security vulnerability CVE-2025-63811.
SECURITY:
CHANGES:
IMPROVEMENTS:
sys/reporting/scan endpoint which will output a set of files containing information about Vault state to the location specified by the reporting_scan_directory config item.vault.route.read-snapshot.{mount_point} and vault.route.list-snapshot.{mount_point} metrics.server_flag, client_flag, code_signing_flag, and email_protection_flag parameters for creating/updating a role.BUG FIXES:
alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.key_usage extension so details accurately reflect certificate values.basic_constraints_valid_for_non_ca is correctly set.Nothing published for this version
core: Update github.com/hashicorp/go-getter to fix security vulnerability GHSA-wjrx-6529-hcj3.
SECURITY:
CHANGES:
recover_snapshot_id query parameter to pass the snapshot ID for recover operations, in favor of a X-Vault-Recover-Snapshot-Id header. Vault will still accept the query parameter for backward compatibility. Also support setting the HTTP method to RECOVER for recover operations, in addition to POST and PUT.timestamp in export API response to token_creation_time.max_json_depth, max_json_string_value_length, max_json_object_entry_count, max_json_array_element_count.FEATURES:
enable_self_enrollment parameter in the API.IMPROVEMENTS:
-download option for plugin register (beta)vault recover command with a -from flag, users can specify the path of the item in the snapshot.enterprise_url field to enable support for self-hosted GitHub Enterprise Server instances.sys/internal/counters/activity/cumulative. For each namespace in the response it returns the sum of its own client counts and that of all its child namespaces.alias_metadata.alias_metadata.alias_metadata.x_forwarded_for_client_cert_header, to fix TLS certificate auth errors with Google Cloud Application Load Balancer.alias_metadata.alias_metadata.alias_metadata.alias_metadata.alias_metadata.alias_metadata.-force flag to vault operator raft snapshot unload command to force deletion of a loaded snapshot.vault.route.read-snapshot.{mount_point} and vault.route.list-snapshot.{mount_point} metrics.force query parameter to the DELETE sys/storage/raft/snapshot-load/{snapshot_id} endpoint to allow for forced deletion of snapshots. This is useful when the snapshot is in a state that prevents normal deletion, such as being in the process of loading.sys/internal/counters/activity/* endpoints.autoload_enabled option to raft automated snapshot configurations. When enabled, this option will automatically load raft snapshots into Vault, which can then be used for recovery operations.role URL query string parameterrole URL query string parameternamespace_path, mount_path and mount_type filters to attribution tableDEPRECATIONS:
BUG FIXES:
development_cluster setting being overwritten on performance secondaries upon cluster reload.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.alias_metadata now populates alias custom metadata field instead of alias metadata.+) paths with existing prefix rules in glob_paths, so clients receive a complete view of glob-style permissions. This unblocks UI sidebar navigation checks and namespace access banners.rotation_statements field.sys/internal/ui/mounts so mount paths match serve value+, *Nothing published for this version
core: Update github.com/ulikunitz/xz to fix security vulnerability GHSA-25xm-hr59-7c27.
SECURITY:
CHANGES:
IMPROVEMENTS:
x_forwarded_for_client_cert_header, to fix TLS certificate auth errors with Google Cloud Application Load Balancer. [GH-31501]BUG FIXES:
core: Update github.com/hashicorp/go-getter to fix security vulnerability GHSA-wjrx-6529-hcj3.
FEATURES:
SECURITY:
CHANGES:
max_json_depth, max_json_string_value_length, max_json_object_entry_count, max_json_array_element_count. [GH-31069]IMPROVEMENTS:
BUG FIXES:
rotation_statements field. [GH-31442]Nothing published for this version
Nothing published for this version
auth/ldap: fix MFA/TOTP enforcement bypass when username_as_alias is enabled [GH-31427,HCSEC-2025-20].
SECURITY:
BUG FIXES:
audit: breaking change privileged vault operator may execute code on the underlying host (CVE-2025-6000). Vault will not unseal if the only configured…
SECURITY:
FEATURES:
IMPROVEMENTS:
-download option for plugin register (beta)BUG FIXES:
development_cluster setting being overwritten on performance secondaries upon cluster reload. [GH-31223]sys/internal/ui/mounts so mount paths match serve value [GH-31094]Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
core/identity: vault root namespace operator may elevate privileges (CVE-2025-5999). Fix string contains check in Identity APIs to be case-insensitive…
SECURITY:
CHANGES:
start_time and end_time in sys/internal/counters/activity are aligned to the corresponding billing period.end_time in sys/internal/counters/activity is now capped at the end of the last completed month. [GH-30164]Retry-After header and, if it exists, wait for the specified duration before retrying the request. [GH-30887]resource_group_name, vm_name, and vmss_name to match token claims [GH-30052]Retry-After value to the nearest second when calculating the retry delay. [GH-30887]namespace, mount_path, mount_type or number of clients for
a selected month. [GH-30678]FormError component (not used) [GH-34699]/vault/auth?with= query parameter [GH-30500]/vault/auth?with= query parameter now exclusively refers to the auth mount path and renders a simplified form [GH-30500]FEATURES:
remove_irrevocable_lease_after. When set to a non-zero value, this will automatically delete irrevocable leases after the configured duration exceeds the lease's expire time. The minimum duration allowed for this field is two days. [GH-30703]development_cluster as a field to Vault's utilization reports.
The field is configurable via HCL and indicates whether the cluster is being used in a development environment, defaults to false if not set. [GH-30659]group_by field to the rate limit quota API to support different grouping modes.IMPROVEMENTS:
/sys/utilization-report, giving a snapshot overview of Vault's utilization at a high level.vault.core.response_status_code, with two labels, code, and type, detailing the status codes of all responses to requests that Vault handles. [GH-30354]vault_index to an event's metadata if the metadata contains modified=true, to support client consistency controls when reading from Vault in response to an event where storage was modified. [GH-30725]VAULT_MYSQL_USERNAME and VAULT_MYSQL_PASSWORD. [GH-30136]listing_visibility="unauth"; all methods can be accessed via the "Sign in with other methods" link [GH-30500]DEPRECATIONS:
/sys/internal/counters/tokens endpoint. Attempting to call this endpoint will return a 403 "unsupported path" exception. [GH-30561]BUG FIXES:
plugin_tmpdir config [GH-29978]plugin_tmpdir configauto_join configurations that include escape characters [GH-29874]NextVaultRotation is nil.
Fixes an issue where static roles were unexpectedly rotated after upgrade due to a missing NextVaultRotation value.
Now sets it to either LastVaultRotation + RotationPeriod or now + RotationPeriod. [GH-30265]private_key after generating [GH-30778]config block [GH-30960]Nothing published for this version
Nothing published for this version
Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
CHANGES:
IMPROVEMENTS:
BUG FIXES:
Nothing published for this version
ui: Replaces all instances of the deprecated event.keyCode with event.key [GH-30493]
Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
CHANGES:
IMPROVEMENTS:
BUG FIXES:
Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
SECURITY:
CHANGES:
BUG FIXES:
plugin_tmpdir config [GH-29978]Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
CHANGES:
BUG FIXES:
NextVaultRotation is nil. Fixes an issue where static roles were unexpectedly rotated after upgrade due to a missing NextVaultRotation value. Now sets it to either LastVaultRotation + RotationPeriod or now + RotationPeriod. [GH-30265]Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
SECURITY:
resource_group_name, vm_name, and vmss_name to match token claims [HCSEC-2025-07 GH-30052].CHANGES:
IMPROVEMENTS:
BUG FIXES:
auto_join configurations that include escape characters. [GH-29874]Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
Enterprise LTS: Vault Enterprise 1.19 is a Long-Term Support (LTS) release.
SECURITY:
CHANGES:
removedcode query parameter. [GH-28991]haunhealthycode query parameter. [GH-28991]FEATURES:
force_identity_deduplication activation flag. [GH-29356]IMPROVEMENTS:
/sys/config/auditing/request-headers/user-agent endpoint. [GH-28596]enable_metadata_on_failures to add client cert metadata on login failures to audit log and response [GH-29044]enable_reauth_on_new_credentials is enabled. [GH-28126]enable_reauth_on_new_credentials, supporting re-authentication when receiving new credential on certain auto-auth types [GH-28126]pprof-dump-dir [GH-27033]removed_from_cluster field to sys/seal-status and vault status output to indicate whether the node has been removed from the HA cluster. [GH-28938]enable_post_unseal_trace and post_unseal_trace_directory config options to generate Go traces during the post-unseal step for debug purposes. [GH-28895]/sys/config/state/sanitized output. [GH-29485]path event metadata field when authorizing a client's subscribe capability for consuming an event, instead of requiring data_path to be present in the event metadata.always_enforce_err within leaf_not_after_behavior to force the error in all circumstances such as CA issuance and ACME requests if requested TTL values are beyond the issuer's NotAfter. [GH-28907]serial_number_source option to PKI roles to control the source for the subject serial number. [GH-29369]BUG FIXES:
template_config is set in one of the config files. [GH-29680]allow_empty_principals in the read role api when key_type is "ca" [GH-28901]connection_url to fix database connection updates (i.e. editing connection config, deleting roles) failing when urls include template variables. [GH-29114]Nothing published for this version
Nothing published for this version
Nothing published for this version
raft/snapshotagent (enterprise): upgrade raft-snapshotagent to v0.2.0
SECURITY:
CHANGES:
FEATURES:
IMPROVEMENTS:
BUG FIXES:
Nothing published for this version
auth/cf: Update plugin to v0.19.1 [GH-29295]
CHANGES:
IMPROVEMENTS:
path event metadata field when authorizing a client's subscribe capability for consuming an event, instead of requiring data_path to be present in the event metadata.BUG FIXES:
Nothing published for this version
secrets/openldap: Update plugin to v0.14.4 [GH-29131]
CHANGES:
IMPROVEMENTS:
enable_post_unseal_trace and post_unseal_trace_directory config options to generate Go traces during the post-unseal step for debug purposes. [GH-28895]BUG FIXES:
connection_url to fix database connection updates (i.e. editing connection config, deleting roles) failing when urls include template variables. [GH-29114]Nothing published for this version
raft/snapshotagent (enterprise): upgrade raft-snapshotagent to v0.0.0-20241115202008-166203013d8e
SECURITY:
CHANGES:
FEATURES:
IMPROVEMENTS:
always_enforce_err within leaf_not_after_behavior to force the error in all circumstances such as CA issuance and ACME requests if requested TTL values are beyond the issuer's NotAfter. [GH-28907]BUG FIXES:
allow_empty_principals in the read role api when key_type is "ca" [GH-28901]core/raft: Add raft join limits [GH-28790, HCSEC-2024-26]
SECURITY:
CHANGES:
IMPROVEMENTS:
BUG FIXES:
Nothing published for this version
Nothing published for this version
ui: Remove deprecated current_billing_period from dashboard activity log request [GH-27559]
SECURITY:
valid_principals to contain a value or default_user be set by default to guard against potentially insecure configurations. allow_empty_principals can be used for backwards compatibility HCSEC-2024-20CHANGES:
allow_empty_principals to allow keys or certs to apply to any user/principal. [GH-28466]IMPROVEMENTS:
current_billing_period from dashboard activity log request [GH-27559]BUG FIXES:
app_name and installation_id are setNothing published for this version
activity (enterprise): filter all fields in client count responses by the request namespace [GH-27790]
CHANGES:
IMPROVEMENTS:
/sys/internal/counters/activity will now include a warning if the specified usage period contains estimated client counts. [GH-28068]vault operator usage will now include a warning if the specified usage period contains estimated client counts. [GH-28068]BUG FIXES:
vault secrets move and vault auth move command will no longer attempt to write to storage on performance standby nodes. [GH-28059]auth/cf: Update plugin to v0.18.0 [GH-27724]
CHANGES:
IMPROVEMENTS:
BUG FIXES:
sys/internal/ui/mounts for a mount prefixed by a namespace path when path filters are configured. [GH-27939]allow_forwarding_via_header to be configured on the cluster. [GH-27891]core: Bump Go version to 1.22.5
CHANGES:
FEATURES:
BUG FIXES:
vault hcp connect where HCP resources with uppercase letters were inaccessible when entering the correct project name. [GH-27694]proxy_protocol_behavior with deny_unauthorized,
which causes the Vault TCP listener to close after receiving an untrusted upstream proxy connection. [GH-27589]auth/jwt: Update plugin to v0.21.0 [GH-27498]
CHANGES:
IMPROVEMENTS:
BUG FIXES:
audit: breaking change - Vault now allows audit logs to contain 'correlation-id' and 'x-correlation-id' headers when they are present in the incoming…
SECURITY:
CHANGES:
enable_multiseal in configuration.namespace label on the vault.kmse.key.count metric.FEATURES:
IMPROVEMENTS:
lease_renewal_threshold, that controls the refresh rate of non-renewable leases in Agent's template engine. [GH-25212]api module. [GH-25744]static_secret_token_capability_refresh_behavior, to control the behavior when the capability refresh request receives an error from Vault.sys/internal/ui/mounts endpoint for auth mount configuration view [GH-26663]password_hash field. [GH-26577]DEPRECATIONS:
BUG FIXES:
vault.namespace no longer gets incorrectly overridden by auto_auth.namespace, if set [GH-26427]/sys/config/auditing)
will now force invalidation and be reloaded from storage when data is replicated
to other nodes.administrative_namespace_path config will now be canonicalized.redact_version listener parameter being ignored for some OpenAPI related endpoints. [GH-26607]chroot_namespace is active, Vault will no longer report that the configuration is invalid when Vault is sealedNothing published for this version
secrets/transit: Use 'hash_algorithm' parameter if present in HMAC verify requests. Otherwise fall back to deprecated 'algorithm' parameter. [GH-27211…
Enterprise LTS: Vault Enterprise 1.16 is a Long-Term Support (LTS) release.
SECURITY:
CHANGES:
IMPROVEMENTS:
BUG FIXES:
redact_version listener parameter being ignored for some OpenAPI related endpoints. [GH-26607]Enterprise LTS: Vault Enterprise 1.16 is a Long-Term Support (LTS) release.
Enterprise LTS: Vault Enterprise 1.16 is a Long-Term Support (LTS) release.
CHANGES:
IMPROVEMENTS:
BUG FIXES:
vault.namespace no longer gets incorrectly overridden by auto_auth.namespace, if set [GH-26427]Your coding agent can read these notes before it upgrades. Set up the MCP server →