HCSEC-2026-33 - HashiCorp Linux Signing GPG Key Update (CA026560)
📋 Description
Bulletin ID: HCSEC-2026-33 Publication Date: September 10, 2026 Last Updated: September 11, 2026 Summary Action is required for customers who install HashiCorp software via our Linux APT or RPM repositories. The HashiCorp GPG key used to sign Linux packages was rotated on September 10th, 2026. The new key fingerprint is D55C 0D1A C78A 8D81 26CB 631C FC9C A96A CA02 6560. The new key fingerprint is also available on our Trust Page (https://www.hashicorp.com/en/trust/security). Background The key rotation was carried out as a precaution following a security incident affecting part of our internal software delivery pipeline. We found no evidence that customer data was accessed, and no evidence that any released software artifact or package was modified or tampered with. As a precaution, we included the GPG key used to sign our public Linux (APT/RPM) packages in our credential review and remediation efforts for the affected environment. Remediation To contain and remediate the incident, HashiCorp revoked unauthorized access and rotated potentially exposed credentials, including rotating our public Linux package-signing GPG key and re-signing the affected packages. Recommended Action Customers who install HashiCorp software via our Linux APT or RPM repositories should import our current signing GPG key, as published in the official HashiCorp packaging guide and above in this bulletin, so that package verification succeeds. Any previously cached or pinned copy of the prior signing key should be replaced. We apologize for this inconvenience. We deeply appreciate any effort to coordinate disclosure of security vulnerabilities. For information about security at HashiCorp and the reporting of security vulnerabilities, please see https://hashicorp.com/security. 1 post - 1 participant Read full topic