Nomad
HashiCorp- Product type
- Other
- Catalog vulnerabilities
- 41
Severity across 21 analyzed records
en
Verify to analyze this security profile
As of 09/13/2026, within CyStack's analyzed data, Nomad has 3 security vulnerabilities published in the last 90 days. Of these, 2 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Nomad and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-14896Nomad vulnerable to cross-namespace host volume claim deletion | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityMedium |
CVE-2026-14891Nomad vulnerable to sandbox escape in Docker task driver | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityHigh |
CVE-2026-14373Nomad Docker driver Linux host namespace bypass | Exploitation statusNot known exploited | FixYes | Published07/08/2026 | SeverityHigh |
CVE-2026-7474Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityHigh |
CVE-2026-6959Nomad vulnerable to arbitrary file read/write on client host through symlink attack | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityMedium |
CVE-2025-4922Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job | Exploitation statusNot known exploited | FixYes | Published06/11/2025 | SeverityHigh |
CVE-2025-3744Nomad Vulnerable To Violation Of Mandatory Sentinel Policies in Nomad Job Submissions via Policy Override | Exploitation statusNot known exploited | FixYes | Published05/13/2025 | SeverityHigh |
CVE-2025-1296Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs | Exploitation statusNot known exploited | FixYes | Published03/10/2025 | SeverityMedium |
CVE-2025-0937Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace | Exploitation statusNot known exploited | FixYes | Published02/12/2025 | SeverityHigh |
CVE-2024-12678Nomad Allocations Vulnerable To Privilege Escalation Within A Namespace Using Unredacted Workload Identity Tokens | Exploitation statusNot known exploited | FixYes | Published12/20/2024 | SeverityMedium |
CVE-2024-10975Nomad Vulnerable To Cross-Namespace Volume Creation Abusing CSI Write Permission | Exploitation statusNot known exploited | FixYes | Published11/07/2024 | SeverityHigh |
CVE-2024-7625Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking | Exploitation statusNot known exploited | FixYes | Published08/14/2024 | SeverityMedium |
CVE-2024-6717Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking | Exploitation statusNot known exploited | FixYes | Published07/23/2024 | SeverityHigh |
CVE-2024-1329Nomad Vulnerable to Arbitrary Write Through Symlink Attack | Exploitation statusNot known exploited | FixYes | Published02/08/2024 | SeverityHigh |
CVE-2023-3300Nomad Search API Leaks Information About CSI Plugins | Exploitation statusNot known exploited | FixYes | Published07/19/2023 | SeverityMedium |
CVE-2023-3299Nomad Caller ACL Token's Secret ID is Exposed to Sentinel | Exploitation statusNot known exploited | FixYes | Published07/19/2023 | SeverityLow |
CVE-2023-3072Nomad ACL Policies without Label are Applied to Unexpected Resources | Exploitation statusNot known exploited | FixYes | Published07/19/2023 | SeverityMedium |
CVE-2023-1782Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation | Exploitation statusNot known exploited | FixYes | Published04/05/2023 | SeverityCritical |
CVE-2023-1299Nomad Job Submitter Privilege Escalation Using Workload Identity | Exploitation statusNot known exploited | FixYes | Published03/14/2023 | SeverityHigh |
CVE-2023-1296Nomad ACLs Can Not Deny Access to Workload's Own Variables | Exploitation statusNot known exploited | FixYes | Published03/14/2023 | SeverityLow |
CVE-2023-0821Nomad Client Vulnerable to Decompression Bombs in Artifact Block | Exploitation statusNot known exploited | FixYes | Published02/16/2023 | SeverityMedium |
CVE-2019-14802 | Exploitation statusNot known exploited | FixYes | Published12/26/2022 | SeverityMedium |
CVE-2022-3867Nomad Event Stream Subscriber Using a Token with TTL Receives Updates Until Garbage Collected | Exploitation statusNot known exploited | FixYes | Published11/10/2022 | SeverityLow |
CVE-2022-3866Nomad Workload Identity Token Can List Non-sensitive Metadata for Paths Under nomad/ | Exploitation statusNot known exploited | FixYes | Published11/10/2022 | SeverityMedium |
CVE-2022-41606 | Exploitation statusNot known exploited | FixYes | Published10/11/2022 | SeverityMedium |
CVE-2022-30324 | Exploitation statusNot confirmed | FixYes | Published05/27/2022 | SeverityUnknown |
CVE-2022-24685 | Exploitation statusNot confirmed | FixYes | Published02/28/2022 | SeverityUnknown |
CVE-2022-24683 | Exploitation statusNot confirmed | FixNot confirmed | Published02/17/2022 | SeverityUnknown |
CVE-2022-24684 | Exploitation statusNot confirmed | FixYes | Published02/15/2022 | SeverityUnknown |
CVE-2022-24686 | Exploitation statusNot confirmed | FixYes | Published02/14/2022 | SeverityUnknown |
CVE-2021-43415 | Exploitation statusNot confirmed | FixYes | Published12/03/2021 | SeverityUnknown |
CVE-2021-41865 | Exploitation statusNot confirmed | FixYes | Published10/07/2021 | SeverityUnknown |
CVE-2021-37218 | Exploitation statusNot confirmed | FixYes | Published09/07/2021 | SeverityUnknown |
CVE-2021-32575 | Exploitation statusNot confirmed | FixYes | Published06/17/2021 | SeverityUnknown |
CVE-2021-3283 | Exploitation statusNot confirmed | FixYes | Published02/01/2021 | SeverityUnknown |
CVE-2020-28348 | Exploitation statusNot confirmed | FixYes | Published11/24/2020 | SeverityUnknown |
CVE-2020-27195 | Exploitation statusNot confirmed | FixYes | Published10/22/2020 | SeverityUnknown |
CVE-2020-10944 | Exploitation statusNot confirmed | FixYes | Published04/28/2020 | SeverityUnknown |
CVE-2020-7956 | Exploitation statusNot confirmed | FixYes | Published01/31/2020 | SeverityUnknown |
CVE-2020-7218 | Exploitation statusNot confirmed | FixYes | Published01/31/2020 | SeverityUnknown |
CVE-2019-12618 | Exploitation statusNot confirmed | FixNot confirmed | Published08/12/2019 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan