HashiCorp memberlist是美国HashiCorp公司的一个基于Gossip协议的集群节点管理组件。 HashiCorp memberlist 0.6.0之前版本存在资源管理错误漏洞,该漏洞源于push/pull状态处理中的拒绝服务问题,可能导致拥有网络访问权限的攻击者通过gossip端口耗尽内存。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Shared library | 0.1.5< 0.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Shared library | 0.1.5 ~ 0.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14891 | 8.7 HIGH | Nomad vulnerable to sandbox escape in Docker task driver |
| CVE-2026-14373 | 7.7 HIGH | Nomad Docker driver Linux host namespace bypass |
| CVE-2026-14361 | 4.7 MEDIUM | Consul-template is vulnerable to path redirection in writeToFile through symlink attack |
| CVE-2026-14896 | 4.2 MEDIUM | Nomad vulnerable to cross-namespace host volume claim deletion |
No comments yet