Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESHASHICORPVERIFIED

PUBLISHER UPDATE · VAULT-2.1.0

VAULT-2.1.0 release notes and known issues

v2.1.0

Scope: HashiCorp Vault. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

2.1.0 September 01, 2026 SECURITY: core: Update go.etcd.io/etcd/client/pkg/v3 to v3.7.1 to fix security vulnerability GO-2026-6107. core: Update software.sslmate.com/src/go-pkcs12 to v0.7.2 to fix security vulnerability GO-2026-5052. CHANGES: License: Add Agentic IAM terms to client licensing model and update terms for Vault Platform licensing model. core: Bump Go version to 1.26.7. oauth-resource-server (enterprise): Prevent issuer_id from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the issuer_id. oauth-resource-server (enterprise): Prevent unique_id_claim from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the unique_id_claim. oauth-resource-server (enterprise): The OAuth Resource Server feature no longer requires activation via the sys/activation-flags/oauth-resource-server/activate endpoint. oauth-resource-server (enterprise): Update OAuth Resource Server config to include custom claim options for the token's unique identifier and actor. secrets/openldap (enterprise): Update plugin to v0.18.4+ent FEATURES: Agent Registry UI (enterprise) : Adds a new Agentic Security section to the primary navigation with an Agent Registry page where operators can view, search, and manage registered AI agents, their associated Vault entities and aliases, assigned policies, and operational status. Automatic DNS-01 Challenge Fulfillment for PKI External CA : Integrate with the following DNS providers for automatic DNS-01 challenge fulfillment: AWS Route53, Azure DNS, Google Cloud DNS, and BIND and other RFC2136-compliant servers. PKI PKCS#12 and JKS Support : Adds support for PKCS#12 (PFX) and Java keytool (JKS) certificate bundles to relevant PKI endpoints. Bundles are returned as base64-encoded, password-protected files. SLH-DSA support for Hybrid sign/verify in Transit engine (enterprise) : Add support for SLH-DSA as the PQC component for Hybrid sign/verify operations. This is compatible with both ECDSA (p-256, P-384, P-521) and Ed25519. secrets/pki-external-ca (enterprise): Add support for handling dns-01 challenges for Azure, AWS, GCP, and rfc2136 DNS. IMPROVEMENTS: agent-registry (enterprise): Removed the restriction that disallowed the use of 'deny' in ceiling policies, resulting in request errors. agent/pkiexternalca: Replace go.uber.org/atomic with sync/atomic (stdlib) for atomic boolean operations in the pkiexternalca package. auth/token: Add global denylist for revoking OAuth JWTs to prevent authorization of specific tokens across all namespaces. core/seal (enterprise): Update Oracle Cloud library to enable seal integration with newer regions. ui: Bump dompurify from 3.4.6 to 3.4.13 . ui: Bump shell-quote from 1.8.4 to 1.9.0. ui: Exposing the RSA Private Key field in the UI when generating credentials with the snowflake database secrets engine. Previously, this field was only shown in the cli. ui: Secrets engine delete confirmation modal now requires typing delete-engine to confirm, displays the engine name, secret count (KV engines only), and a list of what will be permanently deleted. ConfirmModal has now been updated to include a optional type-to-confirm. BUG FIXES: agent/pki-external-ca: Fix CA chain extraction from Vault PKI API responses where ca_chain field was always empty in templates due to incorrect type handling of array responses api: Account for the HTTP Age header when calculating a lease's remaining lifetime, so that leases read or renewed through a caching proxy such as Vault Agent are renewed before they expire. core (enterprise): Fix a data race and potential panic during seal/unseal core (enterprise): Fix panic in collectOperatorImportMetrics when router.Route returns a nil response with no error during KVv2 metadata reads on performance secondary nodes. This condition occurs during the WAL-stream partial-sync phase of an initial join. core/login: Fix panic on malformed login r

Improvements and security content

  • 2.1.0 September 01, 2026 SECURITY: core: Update go.etcd.io/etcd/client/pkg/v3 to v3.7.1 to fix security vulnerability GO-2026-6107. core: Update software.sslmate.com/src/go-pkcs12 to v0.7.2 to fix security vulnerability GO-2026-5052. CHANGES: License: Add Agentic IAM terms to client licensing model and update terms for Vault Platform licensing model. core: Bump Go version to 1.26.7. oauth-resource-server (enterprise): Prevent issuer_id from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the issuer_id. oauth-resource-server (enterprise): Prevent unique_id_claim from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the unique_id_claim. oauth-resource-server (enterprise): The OAuth Resource Server feature no longer requires activation via the sys/activation-flags/oauth-resource-server/activate endpoint. oauth-resource-server (enterprise): Update OAuth Resource Server config to include custom claim options for the token's unique identifier and actor. secrets/openldap (enterprise): Update plugin to v0.18.4+ent FEATURES: Agent Registry UI (enterprise) : Adds a new Agentic Security section to the primary navigation with an Agent Registry page where operators can view, search, and manage registered AI agents, their associated Vault entities and aliases, assigned policies, and operational status. Automatic DNS-01 Challenge Fulfillment for PKI External CA : Integrate with the following DNS providers for automatic DNS-01 challenge fulfillment: AWS Route53, Azure DNS, Google Cloud DNS, and BIND and other RFC2136-compliant servers. PKI PKCS#12 and JKS Support : Adds support for PKCS#12 (PFX) and Java keytool (JKS) certificate bundles to relevant PKI endpoints. Bundles are returned as base64-encoded, password-protected files. SLH-DSA support for Hybrid sign/verify in Transit engine (enterprise) : Add support for SLH-DSA as the PQC component for Hybrid sign/verify operations. This is compatible with both ECDSA (p-256, P-384, P-521) and Ed25519. secrets/pki-external-ca (enterprise): Add support for handling dns-01 challenges for Azure, AWS, GCP, and rfc2136 DNS. IMPROVEMENTS: agent-registry (enterprise): Removed the restriction that disallowed the use of 'deny' in ceiling policies, resulting in request errors. agent/pkiexternalca: Replace go.uber.org/atomic with sync/atomic (stdlib) for atomic boolean operations in the pkiexternalca package. auth/token: Add global denylist for revoking OAuth JWTs to prevent authorization of specific tokens across all namespaces. core/seal (enterprise): Update Oracle Cloud library to enable seal integration with newer regions. ui: Bump dompurify from 3.4.6 to 3.4.13 . ui: Bump shell-quote from 1.8.4 to 1.9.0. ui: Exposing the RSA Private Key field in the UI when generating credentials with the snowflake database secrets engine. Previously, this field was only shown in the cli. ui: Secrets engine delete confirmation modal now requires typing delete-engine to confirm, displays the engine name, secret count (KV engines only), and a list of what will be permanently deleted. ConfirmModal has now been updated to include a optional type-to-confirm. BUG FIXES: agent/pki-external-ca: Fix CA chain extraction from Vault PKI API responses where ca_chain field was always empty in templates due to incorrect type handling of array responses api: Account for the HTTP Age header when calculating a lease's remaining lifetime, so that leases read or renewed through a caching proxy such as Vault Agent are renewed before they expire. core (enterprise): Fix a data race and potential panic during seal/unseal core (enterprise): Fix panic in collectOperatorImportMetrics when router.Route returns a nil response with no error during KVv2 metadata reads on performance secondary nodes. This condition occurs during the WAL-stream partial-sync phase of an initial join. core/login: Fix panic on malformed login r

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • HashiCorp Vault

Affected versions

  • 2.1.0
  • 3.7.1
  • 0.7.2
  • 1.26.7
  • 0.18.4+ent
  • 3.4.6
  • 3.4.13
  • 1.8.4
  • 1.9.0

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence