#OpenBao
I get caught up sometimes on LinkedIn posts and i was directed to this one by Andreas Prins posted Sept 22 about new rancher charts for OpenBao. That seems really sweet. I love Rancher K3s and so i immediately wanted to dig in. I plan to setup OpenBao in K3s th... https://kutt.tpk.pw/uZHTSr
September 29, 2026 at 5:27 AM
[release-26.05] openbao: 2.6.2 -> 2.6.3

https://github.com/NixOS/nixpkgs/pull/567902

#security
September 28, 2026 at 10:35 PM
🔥 GitHub Trending — Sunday, September 27, 2026

#1 paperclip · #2 hindsight · #3 univer · #4 rohitg00 · #5 openbao

#GitHub #OpenSource #Dev
September 27, 2026 at 6:00 AM
Today's GitHub Trending: paperclip manages agents, reverse-skill routes skills, openbao handles secrets. But who governs which agent role can call which skill version? iflytek/skillhub fills that gap: self-hosted skill registry with RBAC, versioning, and audit logs. #AgentGovernance https://github.c
September 26, 2026 at 11:58 PM
📦 openbao / openbao
⭐ 7,519 (+16)
🗒 Go

OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.
GitHub - openbao/openbao: OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.
OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. - openbao/openbao
github.com
September 25, 2026 at 11:17 PM
MCP's spec says protect requestState integrity. It doesn't say where keys live, how replicas share them, or what enforces single-use.

A follow-up on the three operational gaps the SDK leaves open, and how to close them with OpenBao.

https://bit.ly/3VcS57V
September 25, 2026 at 3:00 PM
🚨 CVE-2026-63132 — CVSS 9.2 CRITICAL

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogical...

🔎 https://stemshop.top/cve/CVE-2026-63132

#CVE #CyberSecurity #InfoSec
September 23, 2026 at 8:07 PM
🚨 EUVD-2026-85520
📊 9.2/10
🏢 openbao

📝 OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the h...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85520

#cybersecurity #infosec #cve #euvd
September 23, 2026 at 8:01 PM
🚨 EUVD-2026-83955
📊 7.5/10
🏢 openbao

📝 OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-83955

#cybersecurity #infosec #cve #euvd
September 22, 2026 at 10:02 PM
CVE-2026-63132 - openbao
If OpenBao is run in its special recovery mode, a timing flaw could let a malicious user discover the recovery token. With that token, the attacker could read or change data stored in…

Too many irrelevant or confusing CVEs? Use stackflag.com

#openbao #Golang #CVE #infosec
CVE-2026-63132: OpenBao recovery mode can leak token to attackers
If OpenBao is run in its special recovery mode, a timing flaw could let a malicious user discover the recovery token.
stackflag.com
September 22, 2026 at 9:50 PM
OpenBao's recovery mode let a timing attack extract its recovery token; OpenBao v2.6.0 patches it. The exposure is limited to highly privileged recovery mode. #dev
September 22, 2026 at 9:07 PM
openbao (⭐️ 7456)

OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.

#go
September 22, 2026 at 11:36 AM
CVE-2026-71543 - openbao
OpenBao versions before 2.6.0 let specially crafted characters in policy templates change how access rules are applied. An attacker who can modify those templates could gain higher…

Too many irrelevant or confusing CVEs? Use stackflag.com

#openbao #CVE #infosec
CVE-2026-71543: OpenBao permits privilege escalation through policy wildcards
OpenBao versions before 2.6.0 let specially crafted characters in policy templates change how access rules are applied.
stackflag.com
September 22, 2026 at 4:50 AM
What with Current Events ™️ I’ve been working on replacing 1Password with KeepassXC (for the first time in 12 years?!) and OpenBao (for homelab secrets) and I dare say the UX downgrade offset by the can-I-live-with-myself upgrade feels worth it
September 19, 2026 at 5:44 AM
openbao (⭐️ 7395)

OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.

#go
September 17, 2026 at 4:03 PM
Running OpenBao on Kubernetes with a CloudNativePG PostgreSQL backend www.cncf.io/blog/2026/09... #cncf
Running OpenBao on Kubernetes with a CloudNativePG PostgreSQL backend
Managing infrastructure secrets on Kubernetes needs a backend that is self-healing and free of vendor lock-in, and that is exactly what OpenBao (the Linux Foundation’s open-source fork of HashiCorp…
www.cncf.io
September 17, 2026 at 10:39 AM
OpenBao, Linux Foundation's Vault fork, now runs on Kubernetes with a CloudNativePG PostgreSQL backend for self-healing, vendor-lock-in-free secrets management.
Running OpenBao on Kubernetes with a CloudNativePG PostgreSQL backend
Four Signals — The Wire
www.foursignals.dev
September 16, 2026 at 11:00 PM
openbao (⭐️ 7369)

OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.

#go
September 15, 2026 at 3:26 PM
We're a software consultancy. We maintain the security infrastructure your team owns but nobody owns: PKI and certificate lifecycle, managed Keycloak, Vault, OpenBao. We write and verify codebases in Haskell, Rust, TypeScript. We write and audit smart contracts.
September 14, 2026 at 3:23 AM
Flox v1.16 is out.

Run a package on demand, without creating an environment or installing anything.

Plus: new plugins for 1Password, Vault, OpenBao, and Infisical. Secrets stay with the provider and become available when you activate.

More: buff.ly/XAEDEq8
September 11, 2026 at 4:38 PM
il y a un risque non négligeable de leak. pour ça j'utilise openbao et un approle qui ne lui donne accés à des secrets spécifiques uniquement via des scripts. j'ai mis du temps à mettre ça au point mais j'ai confiance, tu peux aussi utiliser les CLI 1password, passbolt, etc avec des coffres separés
September 8, 2026 at 10:04 AM
It’s pretty wild!

FWIW you might find OpenBao agent sidecars useful for kind of stuff? No need to worry about leaking credentials if they’re painless to rotate
September 6, 2026 at 10:52 PM