HashiCorp nomad是美国HashiCorp公司开源的一个集群管理与调度工具。 HashiCorp nomad存在后置链接漏洞,该漏洞源于Docker任务驱动中的沙箱逃逸问题,可能导致作业提交者即使禁用了卷绑定挂载也能将主机路径绑定挂载到容器中,从而读写主机文件。以下版本受到影响:Nomad 0.4.1版本至2.0.4之前版本及Nomad Enterprise 0.4.1版本至2.0.4之前版本、1.11.8之前版本和1.10.14之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Nomad | 0.4.1< 2.0.4 |
affected |
| HashiCorp | Nomad Enterprise | 0.4.1< 2.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Nomad | 0.4.1 ~ 2.0.4 | - |
|
| HashiCorp | Nomad Enterprise | 0.4.1 ~ 2.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14373 | 7.7 HIGH | Nomad Docker driver Linux host namespace bypass |
| CVE-2026-14362 | 4.9 MEDIUM | Denial of service via crafted push/pull gossip message in memberlist |
| CVE-2026-14361 | 4.7 MEDIUM | Consul-template is vulnerable to path redirection in writeToFile through symlink attack |
| CVE-2026-14896 | 4.2 MEDIUM | Nomad vulnerable to cross-namespace host volume claim deletion |
No comments yet