CVE-2026-87993Consul-template vulnerable to an information disclosure issue in error handling Exploitation status Not known exploited Fix YesAffected product T Tooling Published 09/10/2026 Severity High CVE-2026-88021Consul vulnerable to an authorization bypass in the Connect service mesh Exploitation status Not known exploited Fix YesAffected product C Consul Published 09/10/2026 Severity High CVE-2026-87107Consul vulnerable to an authorization bypass in the catalog deregistration path Exploitation status Not known exploited Fix YesAffected product C Consul Published 09/10/2026 Severity Medium CVE-2026-87106Consul vulnerable to a denial of service in the native RPC listener Exploitation status Not known exploited Fix YesAffected product C Consul Published 09/10/2026 Severity Medium CVE-2026-87090Consul vulnerable to an authorization bypass in the catalog node-write path Exploitation status Not known exploited Fix YesAffected product C Consul Published 09/10/2026 Severity High CVE-2026-5006Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/24/2026 Severity Medium CVE-2026-14978Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions Exploitation status Not known exploited Fix YesAffected product G go-slug Published 08/19/2026 Severity Medium CVE-2026-19589Packer vulnerable to arbitrary file write via crafted plugin archive during installation Exploitation status Not known exploited Fix YesAffected product P Packer Published 08/17/2026 Severity High CVE-2026-8715Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath Exploitation status Not known exploited Fix YesAffected product T Tooling Published 08/13/2026 Severity Critical CVE-2026-14886Vault Enterprise vulnerable to cross-namespace entity deletion Exploitation status Not known exploited Fix YesAffected product V Vault Enterprise Published 08/10/2026 Severity High CVE-2026-12624Vault vulnerable to LIST authorization bypass via trailing-slash strip Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/10/2026 Severity Medium CVE-2026-19113Unauthenticated denial of service via unbounded request body processing Exploitation status Not known exploited Fix YesAffected product C Consul Published 08/07/2026 Severity Medium CVE-2026-15972Unauthenticated denial of service via unbounded external gRPC connection acceptance Exploitation status Not known exploited Fix YesAffected product C Consul Published 08/07/2026 Severity High CVE-2026-15970L7 intention authorization bypass via custom public listener Exploitation status Not known exploited Fix YesAffected product C Consul Published 08/07/2026 Severity Medium CVE-2026-19017Consul vulnerable to partial arbitrary file read via Vault Connect CA provider Exploitation status Not known exploited Fix YesAffected product C Consul Published 08/07/2026 Severity Medium CVE-2026-19015Uncontrolled resource consumption in the Consul Connect CA roots endpoint Exploitation status Not known exploited Fix YesAffected product C Consul Published 08/07/2026 Severity Medium CVE-2026-19014Uncontrolled resource consumption in the Consul Connect authorization endpoint Exploitation status Not known exploited Fix YesAffected product C Consul Published 08/07/2026 Severity Medium CVE-2026-19012Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path Exploitation status Not known exploited Fix YesAffected product C Consul Published 08/07/2026 Severity Medium CVE-2026-19016Authorization bypass for session deletion in the transaction API Exploitation status Not known exploited Fix YesAffected product C Consul Published 08/07/2026 Severity Medium CVE-2026-16326consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode Exploitation status Not known exploited Fix YesAffected product T Tooling Published 07/29/2026 Severity Critical CVE-2026-16328consul-mcp-server vulnerable to server side request forgery leading to token exposure Exploitation status Not known exploited Fix YesAffected product T Tooling Published 07/29/2026 Severity High CVE-2026-16498terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode Exploitation status Not known exploited Fix YesAffected product T Tooling Published 07/28/2026 Severity Critical CVE-2026-16496terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user Exploitation status Not known exploited Fix YesAffected product T Tooling Published 07/28/2026 Severity High CVE-2026-14869terraform-mcp-server vulnerable to server side request forgery leading to token exposure Exploitation status Not known exploited Fix YesAffected product T Tooling Published 07/28/2026 Severity High CVE-2026-14896Nomad vulnerable to cross-namespace host volume claim deletion Exploitation status Not known exploited Fix YesAffected product N Nomad Published 07/08/2026 Severity Medium CVE-2026-14361Consul-template is vulnerable to path redirection in writeToFile through symlink attack Exploitation status Not known exploited Fix YesAffected product T Tooling Published 07/08/2026 Severity Medium CVE-2026-14891Nomad vulnerable to sandbox escape in Docker task driver Exploitation status Not known exploited Fix YesAffected product N Nomad Published 07/08/2026 Severity High CVE-2026-14373Nomad Docker driver Linux host namespace bypass Exploitation status Not known exploited Fix YesAffected product N Nomad Published 07/08/2026 Severity High CVE-2026-14362Denial of service via crafted push/pull gossip message in memberlist Exploitation status Not known exploited Fix YesAffected product S Shared library Published 07/08/2026 Severity Medium CVE-2026-14468Path traversal allows arbitrary file read in Terraform Enterprise container Exploitation status Not known exploited Fix YesAffected product T Terraform Enterprise Published 07/06/2026 Severity High CVE-2026-5051Audit Log Plugin Directory Guard Bypass via Legacy path Option Exploitation status Not known exploited Fix YesAffected product V Vault Published 07/01/2026 Severity Medium CVE-2026-7474Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution Exploitation status Not known exploited Fix YesAffected product N Nomad Published 05/12/2026 Severity High CVE-2026-8052Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack Exploitation status Not known exploited Fix YesAffected product S Shared library Published 05/12/2026 Severity Medium CVE-2026-6959Nomad vulnerable to arbitrary file read/write on client host through symlink attack Exploitation status Not known exploited Fix YesAffected product N Nomad Published 05/12/2026 Severity Medium CVE-2026-5061Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack Exploitation status Not known exploited Fix YesAffected product T Tooling Published 05/12/2026 Severity Medium CVE-2026-7776Boundary Workers Vulnerable to Denial of Service During TLS Handshake Exploitation status Not known exploited Fix YesAffected product B Boundary Published 05/04/2026 Severity High CVE-2026-5807Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations Exploitation status Not known exploited Fix YesAffected product V Vault Published 04/17/2026 Severity High CVE-2026-4525Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header Exploitation status Not known exploited Fix YesAffected product V Vault Published 04/17/2026 Severity High CVE-2026-5052Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS Exploitation status Not known exploited Fix YesAffected product V Vault Published 04/17/2026 Severity Medium CVE-2026-3605Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service Exploitation status Not known exploited Fix YesAffected product V Vault Published 04/17/2026 Severity High CVE-2026-4660Go-getter may allow to arbitrary filesystem reads through git operations Exploitation status Not known exploited Fix YesAffected product T Tooling Published 04/09/2026 Severity High CVE-2026-2808Consul vulnerable to arbitrary file reads through the vault kubernetes authentication provider Exploitation status Not known exploited Fix YesAffected product C Consul Published 03/11/2026 Severity Medium CVE-2026-0969Arbitrary code execution in React server-side rendering of untrusted MDX content Exploitation status Not known exploited Fix YesAffected product S Shared library Published 02/12/2026 Severity High CVE-2025-13357Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method Exploitation status Not known exploited Fix YesAffected product T Tooling Published 11/21/2025 Severity High CVE-2025-13432Terraform Enterprise state versions can be created by users with specific permissions without sufficient write access Exploitation status Not known exploited Fix YesAffected product T Terraform Enterprise Published 11/21/2025 Severity Medium CVE-2025-11374Consul's KV endpoint is vulnerable to denial of service Exploitation status Not known exploited Fix YesAffected product C Consul Published 10/28/2025 Severity Medium CVE-2025-11375Consul's event endpoint is vulnerable to denial of service Exploitation status Not known exploited Fix YesAffected product C Consul Published 10/28/2025 Severity Medium CVE-2025-12044Vault Vulnerable to Denial of Service Due to Rate Limit Regression Exploitation status Not known exploited Fix YesAffected product V Vault Published 10/23/2025 Severity High CVE-2025-11621Vault AWS auth method bypass due to AWS client cache Exploitation status Not known exploited Fix YesAffected product V Vault Published 10/23/2025 Severity High CVE-2025-6203Vault unauthenticated denial of service through complex json payload Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/28/2025 Severity High CVE-2025-8959HashiCorp go-getter Vulnerable to Arbitrary Read through Symlink Attack Exploitation status Not known exploited Fix YesAffected product S Shared library Published 08/15/2025 Severity High CVE-2025-6013Vault LDAP MFA Enforcement Bypass When Using Username As Alias Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/06/2025 Severity Medium CVE-2025-6015Vault Login MFA Bypass of Rate Limiting and TOTP Code Reuse Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/01/2025 Severity Medium CVE-2025-6011Timing Side-Channel in Vault’s Userpass Auth Method Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/01/2025 Severity Low CVE-2025-6004Vault Userpass and LDAP User Lockout Bypass Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/01/2025 Severity Medium CVE-2025-6037Vault Certificate Auth Method Did Not Validate Common Name For Non-CA Certificates Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/01/2025 Severity Medium CVE-2025-6014Vault TOTP Secrets Engine Code Reuse Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/01/2025 Severity Medium CVE-2025-6000Arbitrary Remote Code Execution via Plugin Catalog Abuse Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/01/2025 Severity Critical CVE-2025-5999Vault Root Namespace Operator May Elevate Token Privileges Exploitation status Not known exploited Fix YesAffected product V Vault Published 08/01/2025 Severity High CVE-2025-4656Vault Vulnerable to Recovery Key Cancellation Denial of Service Exploitation status Not known exploited Fix YesAffected product V Vault Published 06/25/2025 Severity Low CVE-2025-4922Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job Exploitation status Not known exploited Fix YesAffected product N Nomad Published 06/11/2025 Severity High CVE-2025-3744Nomad Vulnerable To Violation Of Mandatory Sentinel Policies in Nomad Job Submissions via Policy Override Exploitation status Not known exploited Fix YesAffected product N Nomad Enterprise Published 05/13/2025 Severity High CVE-2025-3879Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login Exploitation status Not known exploited Fix YesAffected product V Vault Published 05/02/2025 Severity Medium CVE-2025-4166Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin Exploitation status Not known exploited Fix YesAffected product V Vault Published 05/02/2025 Severity Medium CVE-2025-1296Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs Exploitation status Not known exploited Fix YesAffected product N Nomad Published 03/10/2025 Severity Medium CVE-2025-1293HashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication Bypass Exploitation status Not known exploited Fix YesAffected product T Tooling Published 02/20/2025 Severity High CVE-2025-0937Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace Exploitation status Not known exploited Fix YesAffected product N Nomad Published 02/12/2025 Severity High CVE-2025-0377HashiCorp go-slug Vulnerable to Zip Slip Attack Exploitation status Not known exploited Fix YesAffected product S Shared library Published 01/21/2025 Severity High CVE-2024-12678Nomad Allocations Vulnerable To Privilege Escalation Within A Namespace Using Unredacted Workload Identity Tokens Exploitation status Not known exploited Fix YesAffected product N Nomad Published 12/20/2024 Severity Medium CVE-2024-12289Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service Exploitation status Not known exploited Fix YesAffected product B Boundary Published 12/12/2024 Severity Medium CVE-2024-10975Nomad Vulnerable To Cross-Namespace Volume Creation Abusing CSI Write Permission Exploitation status Not known exploited Fix YesAffected product N Nomad Published 11/07/2024 Severity High CVE-2024-8185Vault Vulnerable to Denial of Service When Processing Raft Join Requests Exploitation status Not known exploited Fix YesAffected product V Vault Published 10/31/2024 Severity High CVE-2024-10086Consul Vulnerable To Reflected XSS On Content-Type Error Manipulation Exploitation status Not known exploited Fix YesAffected product C Consul Published 10/30/2024 Severity Medium CVE-2024-10006Consul L7 Intentions Vulnerable To Headers Bypass Exploitation status Not known exploited Fix YesAffected product C Consul Published 10/30/2024 Severity High CVE-2024-10005Consul L7 Intentions Vulnerable To URL Path Bypass Exploitation status Not known exploited Fix YesAffected product C Consul Published 10/30/2024 Severity High CVE-2024-10228Vagrant VMWare Utility installation files vulnerable to modification by unprivileged user Exploitation status Not known exploited Fix YesAffected product V Vagrant Published 10/29/2024 Severity Low CVE-2024-9180Vault Operators in Root Namespace May Elevate Their Privileges Exploitation status Not known exploited Fix YesAffected product V Vault Published 10/10/2024 Severity High CVE-2024-7594Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default Exploitation status Not known exploited Fix YesAffected product V Vault Published 09/26/2024 Severity High CVE-2024-8365Vault Leaks AppRole Client Tokens And Accessor in Audit Log Exploitation status Not known exploited Fix YesAffected product V Vault Published 09/02/2024 Severity Medium CVE-2024-7625Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking Exploitation status Not known exploited Fix YesAffected product N Nomad Published 08/14/2024 Severity Medium CVE-2024-6717Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking Exploitation status Not known exploited Fix YesAffected product N Nomad Published 07/23/2024 Severity High CVE-2024-6468Vault Vulnerable to Denial of Service When Setting a Proxy Protocol Behavior Exploitation status Not known exploited Fix YesAffected product V Vault Published 07/11/2024 Severity High CVE-2024-6257HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation Exploitation status Not known exploited Fix YesAffected product S Shared library Published 06/25/2024 Severity High CVE-2024-6104go-retryablehttp can leak basic auth credentials to log files Exploitation status Not known exploited Fix YesAffected product S Shared library Published 06/24/2024 Severity Medium CVE-2024-5798Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims Exploitation status Not known exploited Fix YesAffected product V Vault Published 06/12/2024 Severity Low CVE-2024-2877Vault Enterprise Leaks Sensitive HTTP Request Headers in the Audit Log When Deployed With a Performance Standby Node Exploitation status Not known exploited Fix YesAffected product V Vault Enterprise Published 04/30/2024 Severity Medium CVE-2024-3817HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches Exploitation status Not known exploited Fix YesAffected product S Shared library Published 04/17/2024 Severity Critical CVE-2024-2660Vault TLS Cert Auth Method Did Not Correctly Validate OCSP Responses Exploitation status Not known exploited Fix YesAffected product V Vault Published 04/04/2024 Severity Medium CVE-2024-2048Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificates Exploitation status Public exploit Fix YesAffected product V Vault Published 03/04/2024 Severity High CVE-2024-1329Nomad Vulnerable to Arbitrary Write Through Symlink Attack Exploitation status Not known exploited Fix YesAffected product N Nomad Published 02/08/2024 Severity High CVE-2024-1052Boundary Vulnerable to Session Hijacking Through TLS Certificate Tampering Exploitation status Not known exploited Fix YesAffected product B Boundary Published 02/05/2024 Severity High CVE-2024-0831Vault May Expose Sensitive Information When Configuring An Audit Log Device Exploitation status Not known exploited Fix YesAffected product V Vault Published 02/01/2024 Severity Medium CVE-2023-6337Vault May be Vulnerable to a Denial of Service Through Memory Exhaustion When Handling Large HTTP Requests Exploitation status Not confirmed Fix YesAffected product V Vault Published 12/08/2023 Severity High CVE-2023-5332Dependency on Vulnerable Third-Party Component in GitLab Exploitation status Not confirmed Fix YesAffected product G GitLab Published 12/04/2023 Severity Medium CVE-2023-5954Vault Requests Triggering Policy Checks May Lead To Unbounded Memory Consumption Exploitation status Not confirmed Fix YesAffected product V Vault Published 11/09/2023 Severity Medium CVE-2023-5834Vagrant’s Windows Installer Allowed Directory Junction Write Exploitation status Not known exploited Fix YesAffected product V Vagrant Published 10/27/2023 Severity Low CVE-2023-5077Vault's Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets Exploitation status Not known exploited Fix YesAffected product V Vault Published 09/28/2023 Severity High CVE-2023-3775Vault Enterprise's Sentinel RGP Policies Allowed For Cross-Namespace Denial of Service Exploitation status Not known exploited Fix YesAffected product V Vault Enterprise Published 09/28/2023 Severity Medium CVE-2023-4680Vault's Transit Secrets Engine Allowed Nonce Specified without Convergent Encryption Exploitation status Not known exploited Fix YesAffected product V Vault Published 09/14/2023 Severity Medium CVE-2023-4782Terraform Allows Arbitrary File Write During Init Operation Exploitation status Not known exploited Fix YesAffected product T Terraform Published 09/08/2023 Severity Medium