consul-template 库的错误处理路径中存在一个信息泄露漏洞,可能导致 Vault 密钥的值出现在模板错误消息、日志输出以及下游表面(如 Nomad 任务事件)中。该漏洞(CVE-2026-87993)已在 consul-template 0.43.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87090 | 8.3 HIGH | Consul vulnerable to an authorization bypass in the catalog node-write path |
| CVE-2026-88021 | 7.5 HIGH | Consul vulnerable to an authorization bypass in the Connect service mesh |
| CVE-2026-87106 | 6.5 MEDIUM | Consul vulnerable to a denial of service in the native RPC listener |
| CVE-2026-87107 | 5.4 MEDIUM | Consul vulnerable to an authorization bypass in the catalog deregistration path |
No comments yet