This release includes 5 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Light signalOpenBao v2.6.0 delivers numerous bug fixes and API adjustments across command, server, and auth components.
Why it matters: Addresses crash‑prone token retrieval, audit‑log gaps, and dependency updates; operators should upgrade to stabilize deployments.
Summary
AI summaryBroad release touches BUG FIXES, DEPRECATIONS, command/server, and api.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Fix LIST ACL deny bypass caused by wildcards (#3389 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3474 Fix LIST ACL deny bypass caused by wildcards (#3389 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3474 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Security | Medium |
Fix ACL templates allow wildcard chars in substitution (#3401 by @phil9909) backported by @satoqz in https://github.com/openbao/openbao/pull/3473 Fix ACL templates allow wildcard chars in substitution (#3401 by @phil9909) backported by @satoqz in https://github.com/openbao/openbao/pull/3473 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Security | Medium |
Switch to constant-time comparison recovery token (#3388 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3472 Switch to constant-time comparison recovery token (#3388 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3472 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Security | Medium |
Support Login MFA in profile engine (#3465 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3471 Support Login MFA in profile engine (#3465 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3471 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Security | Low |
Ensure templates do not render secrets to stdout (#3494 by @cipherboy) backported by @cipherboy in https://github.com/openbao/openbao/pull/3495 Ensure templates do not render secrets to stdout (#3494 by @cipherboy) backported by @cipherboy in https://github.com/openbao/openbao/pull/3495 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Propagate keyring updates of all namespaces to standby nodes (#3409 by @wslabosz-reply) backported by @cipherboy in https://github.com/openbao/openbao/pull/3491 Propagate keyring updates of all namespaces to standby nodes (#3409 by @wslabosz-reply) backported by @cipherboy in https://github.com/openbao/openbao/pull/3491 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Fix removal of config-based audit device (#3488 by @satoqz) backported by @cipherboy in https://github.com/openbao/openbao/pull/3492 Fix removal of config-based audit device (#3488 by @satoqz) backported by @cipherboy in https://github.com/openbao/openbao/pull/3492 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Rename substitutions -> identity templates (#3470 by @cipherboy) backported by @cipherboy in https://github.com/openbao/openbao/pull/3493 Rename substitutions -> identity templates (#3470 by @cipherboy) backported by @cipherboy in https://github.com/openbao/openbao/pull/3493 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Add changelog for v2.6.0 GA by @satoqz in https://github.com/openbao/openbao/pull/3496 Add changelog for v2.6.0 GA by @satoqz in https://github.com/openbao/openbao/pull/3496 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Other | Low |
Add changelog entry for LDAP, Kerberos, and RADIUS by @cipherboy in https://github.com/openbao/openbao/pull/3371 Add changelog entry for LDAP, Kerberos, and RADIUS by @cipherboy in https://github.com/openbao/openbao/pull/3371 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
Add T Cloud Public KMS seal doc (#3376 by @mrclki) backported by @phil9909 in https://github.com/openbao/openbao/pull/3392 Add T Cloud Public KMS seal doc (#3376 by @mrclki) backported by @phil9909 in https://github.com/openbao/openbao/pull/3392 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
Fix source tarball release (#3356 by @satoqz) backported by @phil9909 in https://github.com/openbao/openbao/pull/3393 Fix source tarball release (#3356 by @satoqz) backported by @phil9909 in https://github.com/openbao/openbao/pull/3393 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
Add patch support to OpenAPI schema (#3289 by @cipherboy) backported by @phil9909 in https://github.com/openbao/openbao/pull/3394 Add patch support to OpenAPI schema (#3289 by @cipherboy) backported by @phil9909 in https://github.com/openbao/openbao/pull/3394 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
fix(command): revoke self-init root token (#3346 by @dc-tec) backported by @phil9909 in https://github.com/openbao/openbao/pull/3395 fix(command): revoke self-init root token (#3346 by @dc-tec) backported by @phil9909 in https://github.com/openbao/openbao/pull/3395 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
Bump github.com/hashicorp/go-discover from 1.2.0 to 1.3.0 (#3364 by @dependabot) backported by @phil9909 in https://github.com/openbao/openbao/pull/3397 Bump github.com/hashicorp/go-discover from 1.2.0 to 1.3.0 (#3364 by @dependabot) backported by @phil9909 in https://github.com/openbao/openbao/pull/3397 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
Update mount, auth, and namespace limits (#3424 by @cipherboy) backported by @phil9909 in https://github.com/openbao/openbao/pull/3444 Update mount, auth, and namespace limits (#3424 by @cipherboy) backported by @phil9909 in https://github.com/openbao/openbao/pull/3444 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
Adjust `sys/raw` endpoint interaction with implicitly sealed namespaces (#3426 by @wslabosz-reply) backported by @phil9909 in https://github.com/openbao/openbao/pull/3467 Adjust `sys/raw` endpoint interaction with implicitly sealed namespaces (#3426 by @wslabosz-reply) backported by @phil9909 in https://github.com/openbao/openbao/pull/3467 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
fix(sink): in-memory token retrieval panics if unset (#3462 by @nicbaz) backported by @phil9909 in https://github.com/openbao/openbao/pull/3468 fix(sink): in-memory token retrieval panics if unset (#3462 by @nicbaz) backported by @phil9909 in https://github.com/openbao/openbao/pull/3468 Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Other | Low |
Fix missing request ID in audit log for help operations (#3440 by @Flamefire) backported by @phil9909 in https://github.com/openbao/openbao/pull/3469 Fix missing request ID in audit log for help operations (#3440 by @Flamefire) backported by @phil9909 in https://github.com/openbao/openbao/pull/3469 Source: llm_adapter@2026-07-14 Confidence: low |
— |
Full changelog
FEATURES
- Namespace Sealing: Allow Shamir seal configuration on namespace creation. [GH-3297]
- Partitions tenant storage with distinct cryptographic key material.
- Allows tenants to revoke access to their namespace via seal operation without impacting other tenants.
- Uses global synchronization of namespace seal status, allowing easier management from multi-node deployments.
- Auto Unseal plugins: Add a new
kmsplugin type that enables Auto Unseal mechanisms to be distributed as external binary plugins. [GH-2586]- Declaratively register KMS plugins via
plugin "kms" "name" { }stanzas in the server configuration, making"name"available as an Auto Unseal mechanism viaseal "name" { }. - KMS plugins automatically restart and recover from crashes, avoiding a full instance restart when a seal reaches a bad state (e.g., via a misbehaving PKCS#11 library).
- Pre-built plugins for many of the seals currently built into OpenBao are available at https://github.com/openbao/openbao-plugins. A plugin-based seal takes priority over a built-in seal if a matching plugin is installed. Note that several provider-specific built-in seals will be removed from OpenBao in v2.7.0 and remain available as external plugins only. Also see the deprecations section of these release notes.
- Develop custom Auto Unseal mechanisms tailored to your use case using the SDK.
- Declaratively register KMS plugins via
- Workflows: This adds new endpoints under
sys/workflowsto allow operators to create workflows and users to execute them.- Workflows allow the creation of simplified or managed interfaces over OpenBao's standard API.
- Use of the
allow_unauthenticated_workflowsserver configuration value enables unauthenticated execution of workflows; any dispatched requests still require authentication but this can be provided as a request parameter. - Workflows are built on the common profile engine powering declarative self-initialization and use the same syntax. [GH-2728]
- Authenticated root generation: New
/sys/generate-root-tokenendpoints are available as replacements for the deprecated unauthenticated ones. [GH-3041] - Distroless container images: This is a new container image variant based on distroless/static, available as
openbao-distroless. The only executable contained in these images is OpenBao itself. [GH-2592]
SECURITY
- command/agent: Ensure previously rendered secrets do not appear in stdout on failures. GHSA-444v-8vxr-p36h. [GH-3494]
- core/recovery: Use constant-time token comparison in recovery mode. GHSA-34fc-gh42-pj53. [GH-3388]
- core/policies: Prevent LIST operations bypassing
capabilities = ["deny"]from a more specific wildcard ACL grant. GHSA-xp3c-3jw3-4vcr. [GH-3389] - core/policies: If the value of a template expression contains a
+or*character, it will now be rejected by default. Setallow_wildcards_in_identity_templates = trueto overwrite. GHSA-59w7-v8rr-pr4p. [GH-3401] - core/policies: If the value of a template expression contains a
/character, it will now be rejected by default. Setallow_slashes_in_identity_templates = trueto overwrite. GHSA-59w7-v8rr-pr4p. [GH-3401] - secret/pki: If the value of a template expression in
allowed_uri_sans_templateandallowed_domainscontains a*character, it will now be rejected by default. Setallow_globs_in_identity_templates = trueto overwrite. GHSA-59w7-v8rr-pr4p. [GH-3401] - secret/ssh: If the value of a template expression in
allowed_usersorallowed_domainscontains a,character, it will now be rejected by default. Setallow_commas_in_identity_templates = trueto overwrite. GHSA-59w7-v8rr-pr4p. [GH-3401]
IMPROVEMENTS
- command: Allow overriding the location of
~/.vault-tokenvia theBAO_TOKEN_PATHenvironment variable. [GH-2706] - command/server: Error when unknown keys are present in the declarative self-initialization configuration. [GH-2883]
- command/server: Add CEL support to self-initialization, allowing finer control over structuring requests. [GH-2671]
- command/server: Add
text/templatesupport to self-initialization, allowing templating of values from other requests/responses. [GH-2727] - command/server: Allow conditional execution of self-initialization requests with
whenkeyword. [GH-2739] - command/server: Allow self-initialization stanzas in development server mode. [GH-2463]
- command/server: Allow setting headers on declarative self-initialization requests. [GH-2737]
- command/agent: Add
uidandgidconfiguration options for thefilesink. [GH-2851] - command/agent:
SIGHUPnow reloads the client TLS configuration. [GH-3038] - command/login: Support Kubernetes service account token authentication via
-method=kuberneteswith both interactive and non-interactive modes. [GH-1891] - http: Always include full JSON parse and complexity errors in the response instead of hiding it behind a constant error message. [GH-3240]
- http: Ensure that
passthrough_request_headerscan pass theHostheader to plugins. [GH-3325] - core: The
sys/backend is now a singleton shared across all namespaces, reducing idle memory usage of the OpenBao instance. [GH-3007] - core/leases: Lease lookup responses will now include
path,namespace_pathandrevoke_error. [GH-1906] - core/listeners: Add a parameter to allow cross-origin requests to include credentials (
Access-Control-Allow-Credentialsheader). [GH-2262] - core/profiles: Canonicalize headers before evaluating request. [GH-3465]
- core/profiles: Parse login MFA from request header information. [GH-3465]
- seal/azurekeyvault: Support explicitly setting Azure authentication methods and add support for authenticating using Azure managed identities. [GH-2519]
- seal/pkcs11: When using public/private key encryption, fall back to finding the public key via the private key's
CKA_IDif both key halves did not share the sameCKA_LABEL. [GH-3231] - physical/raft: Detect, log, and rollback transactions that have never been committed or rolled-back. If you see the message "transaction was leaked" in your logs, please open an issue. [GH-2185]
- physical/raft: Improve snapshot duration while slightly increasing snapshot size. [GH-3061]
- physical/raft: Support
auto_joinvia DNSSRVrecords. [GH-3397] - auth/cert: Add support for
X-Tls-Client-Cert, to allow processing of a leaf certificate forwarded from a TLS-terminating reverse proxy. [GH-2080] - auth/jwt: Add new Kubernetes JWT provider that authenticates to the Kubernetes API using a pod's service account token. [GH-2114]
- auth/kerberos: Add the
decode_pacoption in order to improve compatibility with Kerberos systems. [GH-2211] - auth/userpass: Add
password_hashfield to allow providing a pre-hashed bcrypt password instead of plaintext. [GH-2702] - secrets/pki: Add encode_json and decode_json CEL helpers. [GH-1549]
- secrets/totp: Add
generated,expire_time, andperiodfields to code generation response. [GH-2585] - secrets/ssh: Search for public and private key files if
-public-key-pathand-private-key-pathflags aren't given, respectively. [GH-2419] - database/mysql: Add multi-host connection failover support. Connection URLs can now specify multiple hosts (e.g.,
tcp(host1:3306,host2:3306)) for automatic failover when a host becomes unavailable. [GH-2312] - api, sdk: Add additional constants for commonly used headers. [GH-2323]
- api: Add
ClientCertBytesandClientKeyBytesas possible in-memory cert contents inTLSConfig. [GH-2798] - api: Add first-class support for
/sys/namespacesAPIs via.Sys().CreateNamespace(...)& co. [GH-2955] - api: Add methods to list and scan keys to the KVv1 and KVv2 client. [GH-3220]
- api: Allow disabling automatic configuration from environment variables in the API client via a
DisableEnvironmentfield onConfigand aNewConfigconstructor to create clean client configurations. [GH-2834] - sdk/helper/consts: Add
AllowedJWTSignatureAlgorithmsEAB. [GH-2464] - ui: Add
lang="en"attribute tohtmltag. [GH-2580] - ui: Update EmberJS to v4.12 LTS. [GH-2653]
CHANGES
- command: Remove buffering and delayed release of logs during startup phase of
server,agent,proxy&debugsubcommands. This includes the removal of the undocumented and hidden-disable-gated-logsflag. [GH-2620] - command:
operator generate-rootnow uses the authenticated/sys/generate-root-tokenendpoints instead of the deprecated/sys/generate-rootendpoints. [GH-3190] - core:
net/http.ServeMuxin Go 1.26 now uses a 307 redirect instead of a 301 redirect when given a bare path which doesn't exist in the multiplexer but which a path with a trailing slash exists for. This causes somePOST/PUToperations to fail with a 400 instead of 404, as OpenBao does not allow writes to paths ending in a slash. See also: https://go.dev/doc/go1.26. [GH-3072] - core/identity: Remove corrupt namespace identity groups created prior to v2.5.0 during unseal; affected groups must be recreated by an administrator. Check for
deleting corrupt groupin server startup logs. [GH-2454] - sys/init, sys/rekey/init: The
stored_sharesparameter was removed and will now be ignored. [GH-2662] - sys/seal-status: Renamed misleading
build_dateresponse field tocommit_date. [GH-2678] - sys/version-history: Renamed misleading
build_dateresponse field tocommit_date. [GH-2678] - api: Removed the
StoredSharesfield fromInitRequestandRotateInitRequeststructs. [GH-2662] - api:
(*Sys).GenerateRoot*methods now use the authenticated/sys/generate-root-tokenendpoints instead of the deprecated/sys/generate-rootendpoints. [GH-3190] - packaging: Renamed misleading ldflags definition
BuildDatetoCommitDate. Build systems need to adjust their pipelines to reflect this change. [GH-2678] - packaging/container: Removed
name,maintainer,vendor,version,release,revision,summary, anddescriptionlabels from container images in favor of the already attached OpenContainers labels. If you have tooling that relies on these labels, instruct it to use the OpenContainers labels instead. [GH-2589] - packaging/container: The openbao & openbao-hsm container images now run under the
openbaouser rather than therootuser by default, matching the default behavior of openbao-ubi variants:- Note that the container entrypoint will always drop down to the
openbaouser before starting OpenBao even if started asroot. The additional capabilities are only used pre-startup to automatically fix up permissions of files accessed by OpenBao. [GH-2589] - If you rely on the container initially running as
rootby default, you can revert to this behavior by manually specifying the user in your container engine.
- Note that the container entrypoint will always drop down to the
- packaging/ui: Switch from
yarntopnpm. [GH-2791] - releases: Artifacts on GitHub now follow consistent naming across archives, SBOMs and signatures. Most notably, "x86_64" or "amd64" is now always "amd64", and the operating system is always lowercased. [GH-3209]
- releases: Checksums are now provided as a single, consolidated
checksums.txtartifact as opposed to per-OS checksum files such aschecksums-linux.txt. [GH-3209]
BUG FIXES
- command: Fix
bao operator rotate-keysandbao operator rekeywarning about new key shares when rotating the barrier root key only. [GH-2648] - command/agent: Fix in-memory sink panic when proxying
auth/token/lookup-selfwhile unauthenticated. [GH-3462] - command/server: Revoke the transient root token after declarative self-initialization, including failure paths. [GH-3346]
- core: Propagate keyring upgrades of sealable namespaces to read-enabled standby nodes. [GH-3409]
- core/seal: Fix
/sys/rotate/root/updatereturning a random, unused key share value when rotating the barrier root key using recovery keys. [GH-2648] - core/listeners: Close HTTP servers first before closing the underlying listener. [GH-2703]
- core/namespaces: Fix PATCH on a namespace returning status 500 on missing or nonexistent namespace. [GH-2955]
- core/audit: Ensure config-driven audit mounts are removed from storage when removed from configuration. [GH-3488]
- core/audit: Include
request.idforpath-helpaudit entries [GH-3440] - core/auth: Ensure inline auth does not generate in-memory lease information. [GH-3343]
- core/mfa: Handle invalidation for login MFA within namespaces, ensuring standby nodes respond appropriately on writes. [GH-3283]
- core/workflows: Ensure
logical.Request.Connectionis set to allow certificate auth and login MFA to work. [GH-3465] - seal/pkcs11: Fix "invalid key format" error when
key_idis provided butkey_labelis not. [GH-3231] - seal/pkcs11: Properly strip hex prefix when setting
key_idas hex value. [GH-3231] - physical/raft: Forward bootstrap challenge/answer requests to active node, fixing raft join failures via load balancer. [GH-2976]
- sys/plugin: Fix plugin reload returning success for non-existent plugin. [GH-2398]
- sys/quotas: Fix unintentional attempts to delete quotas on standby nodes when mount is removed. [GH-3316]
- sys/raw: Prevent writes to and return distinctive error reading storage associated with sealed namespaces. [GH-3426]
- secrets/pki: Add missing migration for
not_after_boundandnot_before_boundrole fields. [GH-3031] - secrets/pki:
/sign-verbatimnow preserves the original subject encoding from the CSR. Previously, UTF8String values were re-encoded as PrintableString when the subject contained only ASCII characters. [GH-2861] - openapi: Add missing support for reporting SCAN on endpoints. [GH-2902]
- openapi: Add missing support for reporting PATCH support on endpoints. [GH-3289
DEPRECATIONS
- core/seal: Following the introduction of pluggable Auto Unseal support in this release, the built-in versions of the
alicloudkms,awskms,azurekeyvault,gcpckms,ocikmsandpkcs11Auto Unseal mechanisms will be removed in v2.7.0 and remain available as external plugins only. [GH-2586] - physical/file: Deprecate file storage backend for removal in v2.7.0. [GH-2849]
- packaging, seal/pkcs11: Following the introduction of pluginized HSM/PKCS#11 Auto Unseal support in this release, the HSM distribution of OpenBao will be discontinued by v2.7.0. PKCS#11 support remains available via the PKCS#11 plugin which can be used together with the standard distribution of OpenBao. [GH-2586]
- packaging: Drop builds for 32-bit ARM Windows as part of its removal from Go 1.26. [GH-3191]
- packaging/container: Architecture-specific container image tags such as
openbao/openbao:2.6.0-arm64will not be published starting with this release. Refer to multi-arch container images instead (simplyopenbao/openbao:2.6.0). [GH-3209] - auth/kerberos: The built-in Kerberos auth plugin has been deprecated and slated for removal from the main OpenBao binary distribution in v2.7.0. It will be included in openbao-plugins going forward. [GH-3371]
- auth/ldap: The built-in LDAP auth plugin has been deprecated and slated for removal from the main OpenBao binary distribution in v2.7.0. It will be included in openbao-plugins going forward. [GH-3371]
- auth/radius: The built-in RADIUS auth plugin has been deprecated and slated for removal from the main OpenBao binary distribution in v2.7.0. It will be included in openbao-plugins going forward. [GH-3371]
- secret/ldap: The built-in LDAP secrets plugin has been deprecated and slated for removal from the main OpenBao binary distribution in v2.7.0. It will be included in openbao-plugins going forward. [GH-3371]
New Contributors
- @MatthieuCoder made their first contribution in https://github.com/openbao/openbao/pull/2211
- @kaelres made their first contribution in https://github.com/openbao/openbao/pull/2239
- @Tosta-Mista made their first contribution in https://github.com/openbao/openbao/pull/2279
- @thgoebel made their first contribution in https://github.com/openbao/openbao/pull/2298
- @radoslawszulgo made their first contribution in https://github.com/openbao/openbao/pull/2327
- @boumba100 made their first contribution in https://github.com/openbao/openbao/pull/2333
- @andsens made their first contribution in https://github.com/openbao/openbao/pull/2355
- @gianklug made their first contribution in https://github.com/openbao/openbao/pull/2365
- @mijenne made their first contribution in https://github.com/openbao/openbao/pull/2370
- @ioboi made their first contribution in https://github.com/openbao/openbao/pull/2369
- @oneswig made their first contribution in https://github.com/openbao/openbao/pull/2376
- @ecksun made their first contribution in https://github.com/openbao/openbao/pull/2419
- @AndrewCharlesHay made their first contribution in https://github.com/openbao/openbao/pull/2423
- @kangetsu121 made their first contribution in https://github.com/openbao/openbao/pull/2526
- @stormshield-gt made their first contribution in https://github.com/openbao/openbao/pull/2490
- @operatorequals made their first contribution in https://github.com/openbao/openbao/pull/2542
- @dbanetto made their first contribution in https://github.com/openbao/openbao/pull/2463
- @tongpu made their first contribution in https://github.com/openbao/openbao/pull/2580
- @JAYKRISHNAN made their first contribution in https://github.com/openbao/openbao/pull/2628
- @stephnangue made their first contribution in https://github.com/openbao/openbao/pull/2621
- @XiaoPengMei made their first contribution in https://github.com/openbao/openbao/pull/2723
- @EnricoFusi made their first contribution in https://github.com/openbao/openbao/pull/2702
- @axilleas made their first contribution in https://github.com/openbao/openbao/pull/2788
- @cropalato made their first contribution in https://github.com/openbao/openbao/pull/2312
- @ldesauw made their first contribution in https://github.com/openbao/openbao/pull/2807
- @jon4hz made their first contribution in https://github.com/openbao/openbao/pull/2851
- @janlauber made their first contribution in https://github.com/openbao/openbao/pull/2889
- @gregory-ruch-duokey made their first contribution in https://github.com/openbao/openbao/pull/2906
- @nneul made their first contribution in https://github.com/openbao/openbao/pull/2706
- @nireo made their first contribution in https://github.com/openbao/openbao/pull/3024
- @esticansat made their first contribution in https://github.com/openbao/openbao/pull/2981
- @alexa-gt made their first contribution in https://github.com/openbao/openbao/pull/3038
- @eklatzer made their first contribution in https://github.com/openbao/openbao/pull/3063
- @rndmh3ro made their first contribution in https://github.com/openbao/openbao/pull/3066
- @bfabio made their first contribution in https://github.com/openbao/openbao/pull/3065
- @mpldr made their first contribution in https://github.com/openbao/openbao/pull/3054
- @james-knippes made their first contribution in https://github.com/openbao/openbao/pull/3004
- @szamuboy made their first contribution in https://github.com/openbao/openbao/pull/3104
- @theartusz made their first contribution in https://github.com/openbao/openbao/pull/3217
- @avesst made their first contribution in https://github.com/openbao/openbao/pull/3274
- @abuango made their first contribution in https://github.com/openbao/openbao/pull/3294
- @TheJayMann made their first contribution in https://github.com/openbao/openbao/pull/3325
- @mrclki made their first contribution in https://github.com/openbao/openbao/pull/3376
- @nicbaz made their first contribution in https://github.com/openbao/openbao/pull/3462
- @Flamefire made their first contribution in https://github.com/openbao/openbao/pull/3440
What's Changed
- Add changelog entry for LDAP, Kerberos, and RADIUS by @cipherboy in https://github.com/openbao/openbao/pull/3371
- Add T Cloud Public KMS seal doc (#3376 by @mrclki) backported by @phil9909 in https://github.com/openbao/openbao/pull/3392
- Fix source tarball release (#3356 by @satoqz) backported by @phil9909 in https://github.com/openbao/openbao/pull/3393
- Add patch support to OpenAPI schema (#3289 by @cipherboy) backported by @phil9909 in https://github.com/openbao/openbao/pull/3394
- fix(command): revoke self-init root token (#3346 by @dc-tec) backported by @phil9909 in https://github.com/openbao/openbao/pull/3395
- Bump github.com/hashicorp/go-discover from 1.2.0 to 1.3.0 (#3364 by @dependabot) backported by @phil9909 in https://github.com/openbao/openbao/pull/3397
- Update mount, auth, and namespace limits (#3424 by @cipherboy) backported by @phil9909 in https://github.com/openbao/openbao/pull/3444
- Adjust
sys/rawendpoint interaction with implicitly sealed namespaces (#3426 by @wslabosz-reply) backported by @phil9909 in https://github.com/openbao/openbao/pull/3467 - fix(sink): in-memory token retrieval panics if unset (#3462 by @nicbaz) backported by @phil9909 in https://github.com/openbao/openbao/pull/3468
- Fix missing request ID in audit log for help operations (#3440 by @Flamefire) backported by @phil9909 in https://github.com/openbao/openbao/pull/3469
- Fix LIST ACL deny bypass caused by wildcards (#3389 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3474
- Fix ACL templates allow wildcard chars in substitution (#3401 by @phil9909) backported by @satoqz in https://github.com/openbao/openbao/pull/3473
- Switch to constant-time comparison recovery token (#3388 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3472
- Support Login MFA in profile engine (#3465 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3471
- Fix link to PKI CEL page by @cipherboy in https://github.com/openbao/openbao/pull/3476
- Bump Go to 1.26.5 (#3479 by @satoqz) by @satoqz in https://github.com/openbao/openbao/pull/3480
- Add documentation on CEL for JWT (#3423 by @cipherboy) backported by @phil9909 in https://github.com/openbao/openbao/pull/3484
- Add v2.6.0 to docs website (#3475 by @cipherboy) backported by @satoqz in https://github.com/openbao/openbao/pull/3485
- Pin ubi10-minimal to
b217fa6(#3412 by @dependabot) backported by @phil9909 in https://github.com/openbao/openbao/pull/3445 - Propagate keyring updates of all namespaces to standby nodes (#3409 by @wslabosz-reply) backported by @cipherboy in https://github.com/openbao/openbao/pull/3491
- Fix removal of config-based audit device (#3488 by @satoqz) backported by @cipherboy in https://github.com/openbao/openbao/pull/3492
- Rename substitutions -> identity templates (#3470 by @cipherboy) backported by @cipherboy in https://github.com/openbao/openbao/pull/3493
- Ensure templates do not render secrets to stdout (#3494 by @cipherboy) backported by @cipherboy in https://github.com/openbao/openbao/pull/3495
- Add changelog for v2.6.0 GA by @satoqz in https://github.com/openbao/openbao/pull/3496
Full Changelog: https://github.com/openbao/openbao/compare/v2.5.5...v2.6.0
Breaking Changes
- Removed `-disable-gated-logs` flag from command startup logging.
- Deprecated built‑in auth plugins (Kerberos, LDAP, RADIUS) and secret plugin (LDAP) slated for removal in v2.7.0.
- Dropped architecture‑specific container image tags; only multi‑arch images (`openbao/openbao:2.6.0`) will be published.
Security Fixes
- command/agent: Ensure previously rendered secrets do not appear in stdout on failures. GHSA-444v-8vxr-p36h.
- core/recovery: Use constant‑time token comparison in recovery mode. GHSA-34fc-gh42-pj53.
- core/policies: Prevent LIST operations bypassing `capabilities = ["deny"]` via more specific wildcard ACL grant. GHSA-xp3c-3jw3-4vcr.
- core/policies: Reject template expressions containing `+`, `*`, `/` characters by default; configurable overrides added. GHSA-59w7-v8rr-pr4p (GH‑3401).
- secret/pki, secret/ssh: Reject glob/comma characters in template expressions for PKI and SSH secrets by default; configurable overrides added. GHSA-59w7-v8rr-pr4p (GH‑3401).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About openbao
OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.
Related context
Related tools
Beta — feedback welcome: [email protected]