Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESHASHICORPVERIFIED

PUBLISHER UPDATE · VAULT-2.0.4

VAULT-2.0.4 release notes and known issues

v2.0.4

Scope: HashiCorp Vault. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

2.0.4 August 04, 2026 BREAKING CHANGES: containers: The following packages have been removed from UBI based container images: gnupg, openssl, procps. SECURITY: acl: Fix privilege-escalation vulnerability where a denied_parameters constraint on the policies request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the policies parameter to lowercase before evaluating allowed_parameters / denied_parameters constraints. identity/scim (enterprise): The identity/entity/merge endpoint now rejects requests that involve any SCIM-managed entity, preventing privileged operators from bypassing SCIM ownership guardrails to transfer aliases, group memberships, or policies across SCIM boundaries. identity: Prevent the entity batch-delete endpoint (identity/entity/batch-delete) from deleting the underlying storage of entities that belong to another namespace. identity: entity/name updates now reject mismatched id or external_id selectors to prevent retargeting updates to a different entity CHANGES: auth/oci: Update plugin to v0.21.3 core: Bump Go version to 1.26.5. core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with duplicate attributes now always fails, and the VAULT_ALLOW_PENDING_REMOVAL_DUPLICATE_HCL_ATTRIBUTES environment variable that previously restored the legacy behavior has been removed. FEATURES: secrets: Added ability to view secrets in YAML format IMPROVEMENTS: auth/cert: Support login via x-forwarded cert headers even with tls disabled on the vault listener. core (enterprise): Add an endpoint at sys/config/oauth-resource-server/id/:config_id to read oauth resource server profiles by config_id core (enterprise): Make OAuth resource server JWT typ validation more permissive for tokens from IdPs such as Okta by allowing a missing typ header, while restricting present typ values to at+jwt , application/at+jwt , and JWT . core (entreprise): Ameriolate sealwrap lock contention for core paths. core/acl: Adds a global deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false . core/identity: Adds a global deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false . core/managed-keys/PKCS#11 (enterprise): Providing a non-empty value for one field while the other is already saved is rejected. To switch addressing modes, you must explicitly clear the old field by sending it as an empty string ("") in the same request alongside the new value. core/managed-keys/PKCS#11 (enterprise): slot and token_label are now strictly enforced as mutually exclusive identifiers for an HSM token events: Add VAULT_EVENT_NOTIFICATIONS_BOUNDED_QUEUE_SIZE environment variable to configure bounded event queues for event notification subscribers. Set to a positive integer (e.g., 16) to enable buffered channels of that size (maximum 1000). This prevents resource exhaustion in deployments with high subscriber counts, but comes at the cost of the potential for subscribers to miss events. Defaults to 0 (unbuffered) for backward compatibility. identity/scim (enterprise): Added filtering support to the GET /scim/v2/Users and GET /scim/v2/Groups endpoints per RFC 7644. Supported filters: userName eq , externalId eq , active eq , and meta.lastModified gt/ge/lt/le for Users; displayName eq and meta.lastModified gt/ge/lt/le for Groups. Unsupported filter expressions return HTTP 400. ServiceProviderConfig now advertises filter.supported: true . identity/scim (enterprise): Improve SCIM User and Group listing endpoint performance by using prefix sort instead of a separate sort pass. identity: Include entity status and entity/alias timestamp details in entity list key_info responses. oauth-resource-server: Add support for fine-grained policy control options (par

Improvements and security content

  • 2.0.4 August 04, 2026 BREAKING CHANGES: containers: The following packages have been removed from UBI based container images: gnupg, openssl, procps. SECURITY: acl: Fix privilege-escalation vulnerability where a denied_parameters constraint on the policies request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the policies parameter to lowercase before evaluating allowed_parameters / denied_parameters constraints. identity/scim (enterprise): The identity/entity/merge endpoint now rejects requests that involve any SCIM-managed entity, preventing privileged operators from bypassing SCIM ownership guardrails to transfer aliases, group memberships, or policies across SCIM boundaries. identity: Prevent the entity batch-delete endpoint (identity/entity/batch-delete) from deleting the underlying storage of entities that belong to another namespace. identity: entity/name updates now reject mismatched id or external_id selectors to prevent retargeting updates to a different entity CHANGES: auth/oci: Update plugin to v0.21.3 core: Bump Go version to 1.26.5. core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with duplicate attributes now always fails, and the VAULT_ALLOW_PENDING_REMOVAL_DUPLICATE_HCL_ATTRIBUTES environment variable that previously restored the legacy behavior has been removed. FEATURES: secrets: Added ability to view secrets in YAML format IMPROVEMENTS: auth/cert: Support login via x-forwarded cert headers even with tls disabled on the vault listener. core (enterprise): Add an endpoint at sys/config/oauth-resource-server/id/:config_id to read oauth resource server profiles by config_id core (enterprise): Make OAuth resource server JWT typ validation more permissive for tokens from IdPs such as Okta by allowing a missing typ header, while restricting present typ values to at+jwt , application/at+jwt , and JWT . core (entreprise): Ameriolate sealwrap lock contention for core paths. core/acl: Adds a global deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false . core/identity: Adds a global deny_slash_in_templated_path configuration option to reject the presence of slashes in rendered identity templates in policies, defaulting to false . core/managed-keys/PKCS#11 (enterprise): Providing a non-empty value for one field while the other is already saved is rejected. To switch addressing modes, you must explicitly clear the old field by sending it as an empty string ("") in the same request alongside the new value. core/managed-keys/PKCS#11 (enterprise): slot and token_label are now strictly enforced as mutually exclusive identifiers for an HSM token events: Add VAULT_EVENT_NOTIFICATIONS_BOUNDED_QUEUE_SIZE environment variable to configure bounded event queues for event notification subscribers. Set to a positive integer (e.g., 16) to enable buffered channels of that size (maximum 1000). This prevents resource exhaustion in deployments with high subscriber counts, but comes at the cost of the potential for subscribers to miss events. Defaults to 0 (unbuffered) for backward compatibility. identity/scim (enterprise): Added filtering support to the GET /scim/v2/Users and GET /scim/v2/Groups endpoints per RFC 7644. Supported filters: userName eq , externalId eq , active eq , and meta.lastModified gt/ge/lt/le for Users; displayName eq and meta.lastModified gt/ge/lt/le for Groups. Unsupported filter expressions return HTTP 400. ServiceProviderConfig now advertises filter.supported: true . identity/scim (enterprise): Improve SCIM User and Group listing endpoint performance by using prefix sort instead of a separate sort pass. identity: Include entity status and entity/alias timestamp details in entity list key_info responses. oauth-resource-server: Add support for fine-grained policy control options (par

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • HashiCorp Vault

Affected versions

  • 2.0.4
  • 0.21.3
  • 1.26.5

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence