HashiCorp Security
Vault, Terraform, Nomad, Consul security advisories.
48 advisories tracked · showing 48
- Sep 10, 2026HCSEC-2026-38CVE-2026-87993
HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling
- Sep 10, 2026HCSEC-2026-37CVE-2026-88021
HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh
- Sep 10, 2026HCSEC-2026-36CVE-2026-87107
HCSEC-2026-36 - Consul vulnerable to an authorization bypass in the catalog deregistration path
- Sep 10, 2026HCSEC-2026-35CVE-2026-87106
HCSEC-2026-35 - Consul vulnerable to a denial of service in the native RPC listener
- Sep 10, 2026HCSEC-2026-34CVE-2026-87090
HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path
- Sep 10, 2026HCSEC-2026-33Disclosed before NVD
HCSEC-2026-33 - HashiCorp Linux Signing GPG Key Update (CA026560)
- Aug 24, 2026HCSEC-2026-32CVE-2026-5006
HCSEC-2026-32 - Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
- Aug 20, 2026HCSEC-2026-31CVE-2026-14978
HCSEC-2026-31 - Go-slug vulnerable to exclusion bypass in .terraformignore handling
- Aug 18, 2026HCSEC-2026-30Disclosed before NVD
HCSEC-2026-30 - Updates to HashiCorp subprocessors
- Aug 17, 2026HCSEC-2026-29CVE-2026-19589
HCSEC-2026-29 - Packer vulnerable to arbitrary file write via crafted plugin archive during installation
- Aug 13, 2026HCSEC-2026-28CVE-2026-8715
HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath
- Aug 10, 2026HCSEC-2026-27CVE-2026-14886
HCSEC-2026-27 - Vault Enterprise vulnerable to cross-namespace entity deletion
- Aug 10, 2026HCSEC-2026-26CVE-2026-12624
HCSEC-2026-26 - Vault vulnerable to LIST authorization bypass via trailing-slash strip
- Aug 7, 2026HCSEC-2026-25CVE-2026-15970, CVE-2026-19113 +6
HCSEC-2026-25 - Multiple vulnerabilities impacting HashiCorp Consul
- Jul 29, 2026HCSEC-2026-24CVE-2026-16328, CVE-2026-16326
HCSEC-2026-24 - Multiple vulnerabilities impacting HashiCorp Consul MCP Server
- Jul 28, 2026HCSEC-2026-23CVE-2026-14869, CVE-2026-16496 +1
HCSEC-2026-23 - Multiple vulnerabilities impacting HashiCorp Terraform MCP Server
- Jul 8, 2026HCSEC-2026-22CVE-2026-14896
HCSEC-2026-22 - Nomad vulnerable to cross-namespace host volume claim deletion
- Jul 8, 2026HCSEC-2026-21CVE-2026-14891
HCSEC-2026-21 - Nomad vulnerable to sandbox escape in Docker task driver
- Jul 8, 2026HCSEC-2026-20CVE-2026-14361
HCSEC-2026-20 - Consul-template vulnerable to path redirections in writeToFile
- Jul 8, 2026HCSEC-2026-19CVE-2026-14373
HCSEC-2026-19 - Nomad Docker driver vulnerable to host namespace bypass on Linux
- Jul 8, 2026HCSEC-2026-18CVE-2026-14362
HCSEC-2026-18 - Memberlist vulnerable to denial of service via gossip message
- Jul 6, 2026HCSEC-2026-17CVE-2026-14468
HCSEC-2026-17 - Terraform Enterprise vulnerable to arbitrary file read
- Jul 1, 2026HCSEC-2026-16CVE-2026-5051
HCSEC-2026-16 - Vault Audit Device Plugin Directory Guard Bypass via Legacy Path Option
- May 12, 2026HCSEC-2026-15CVE-2026-7474
HCSEC-2026-15 - Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution
- May 12, 2026HCSEC-2026-14CVE-2026-6959
HCSEC-2026-14 - Nomad arbitrary file read/write on client host through symlink attack
- May 12, 2026HCSEC-2026-13CVE-2026-8052
HCSEC-2026-13 - Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack
- May 12, 2026HCSEC-2026-12CVE-2026-5061
HCSEC-2026-12 - Consul-template vulnerable to sandbox path bypass in file helper through symlink attack
- May 4, 2026HCSEC-2026-11CVE-2026-7776
HCSEC-2026-11 - Boundary Workers Vulnerable to Denial of Service During TLS Handshake
- Apr 27, 2026HCSEC-2026-10Disclosed before NVD
HCSEC-2026-10 - Updates to HashiCorp subprocessors
- Apr 20, 2026HCSEC-2026-09Disclosed before NVD
HCSEC-2026-09 - Remediation and Improved Secret Management for GitHub Webhook Secret Exposure
- Apr 17, 2026HCSEC-2026-08CVE-2026-5807
HCSEC-2026-08 - Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
- Apr 17, 2026HCSEC-2026-07CVE-2026-4525
HCSEC-2026-07 - Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
- Apr 17, 2026HCSEC-2026-06CVE-2026-5052
HCSEC-2026-06 - Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
- Apr 17, 2026HCSEC-2026-05CVE-2026-3605
HCSEC-2026-05 - Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service
- Apr 9, 2026HCSEC-2026-04CVE-2026-4660
HCSEC-2026-04 - Go-getter may allow to arbitrary filesystem reads through git operations
- Mar 12, 2026HCSEC-2026-03Disclosed before NVD
HCSEC-2026-03 - HashiCorp GPG Key (72D7468F) Update
- Mar 11, 2026HCSEC-2026-02CVE-2026-2808
HCSEC-2026-02 - Consul Vulnerable to Arbitrary File Reads Through the Vault Kubernetes Authentication Provider
- Feb 12, 2026HCSEC-2026-01CVE-2026-0969
HCSEC-2026-01 - Arbitrary code execution in React server-side rendering of untrusted MDX content
- Nov 21, 2025HCSEC-2025-33CVE-2025-13357
HCSEC-2025-33 - Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method
- Nov 21, 2025HCSEC-2025-34CVE-2025-13432
HCSEC-2025-34 - Terraform Enterprise state versions can be created by users without sufficient write access
- Oct 28, 2025HCSEC-2025-29CVE-2025-11374
HCSEC-2025-29 - Consul's KV endpoint is vulnerable to denial of service
- Oct 28, 2025HCSEC-2025-28CVE-2025-11375
HCSEC-2025-28 - Consul's event endpoint is vulnerable to denial of service
- Oct 23, 2025HCSEC-2025-32CVE-2025-6203
HCSEC-2025-32 - Incomplete Fix For Previous Vault DoS Issue
- Oct 23, 2025HCSEC-2025-31CVE-2025-12044
HCSEC-2025-31- Vault Vulnerable to Denial of Service Due to Rate Limit Regression
- Oct 23, 2025HCSEC-2025-30CVE-2025-11621
HCSEC-2025-30 - Vault AWS Auth Method Authentication Bypass Through Mishandling of Cache Entries
- Sep 30, 2025HCSEC-2025-25Disclosed before NVD
HCSEC-2025-25 - Updates to HashiCorp subprocessors
- Aug 28, 2025HCSEC-2025-24CVE-2025-6203
HCSEC-2025-24 - Vault Denial of Service Though Complex JSON Payloads
- Aug 15, 2025HCSEC-2025-23CVE-2025-8959
HCSEC-2025-23 - HashiCorp go-getter Vulnerable to Arbitrary Read through Symlink Attack