Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Nomad — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Nomad, with AI-generated Chinese analysis, references, and POCs.

This is a vulnerability aggregation page for the Nomad product from HashiCorp, covering Common Weakness Enumerations. The page collects data regarding security vulnerabilities and misconfigurations associated with Nomad, spanning from its initial public release through the present day. It serves as a comprehensive repository for tracking the evolving security landscape of this container orchestration tool. By browsing this collection, you can track a vendor's advisories to stay informed about official patches and mitigation strategies issued by HashiCorp. You can also understand a weakness class by analyzing patterns across multiple reports, which helps in identifying systemic issues rather than isolated incidents. Additionally, you can look up a product's vulnerability history to assess the long-term security posture and responsiveness of the Nomad development team. This information is critical for security professionals, DevOps engineers, and system administrators who need to evaluate risk, prioritize remediation efforts, and ensure compliance with organizational security standards. The data is organized to facilitate efficient searching and analysis, allowing users to quickly identify relevant findings without sifting through unstructured logs. This structured approach supports proactive security management and helps in making informed decisions about upgrading, configuring, or monitoring Nomad deployments in production environments.

Vendor: HashiCorp

CVE ID Title CVSS Severity Published
CVE-2026-14896 Nomad vulnerable to cross-namespace host volume claim deletion CWE-863 4.2 Medium 2026-07-08
CVE-2026-14891 Nomad vulnerable to sandbox escape in Docker task driver CWE-59 8.7 High 2026-07-08
CVE-2026-14373 Nomad Docker driver Linux host namespace bypass CWE-862 7.7 High 2026-07-08
CVE-2026-7474 Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution CWE-22 8.8 High 2026-05-12
CVE-2026-6959 Nomad vulnerable to arbitrary file read/write on client host through symlink attack CWE-59 6.0 Medium 2026-05-12
CVE-2025-4922 Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job CWE-266 8.1 High 2025-06-11
CVE-2025-1296 Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs CWE-532 6.5 Medium 2025-03-10
CVE-2025-0937 Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace CWE-863 7.1 High 2025-02-12
CVE-2024-12678 Nomad Allocations Vulnerable To Privilege Escalation Within A Namespace Using Unredacted Workload Identity Tokens CWE-266 6.5 Medium 2024-12-20
CVE-2024-10975 Nomad Vulnerable To Cross-Namespace Volume Creation Abusing CSI Write Permission CWE-863 7.7 High 2024-11-07
CVE-2024-7625 Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking CWE-610 5.8 Medium 2024-08-14
CVE-2024-6717 Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking CWE-610 7.7 High 2024-07-23
CVE-2024-1329 Nomad Vulnerable to Arbitrary Write Through Symlink Attack CWE-59 7.7 High 2024-02-08
CVE-2023-3300 Nomad Search API Leaks Information About CSI Plugins CWE-266 5.3 Medium 2023-07-19
CVE-2023-3072 Nomad ACL Policies without Label are Applied to Unexpected Resources CWE-266 4.1 Medium 2023-07-19
CVE-2023-1782 Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation CWE-862 10.0 Critical 2023-04-05
CVE-2023-1299 Nomad Job Submitter Privilege Escalation Using Workload Identity CWE-862 7.4 High 2023-03-14
CVE-2023-1296 Nomad ACLs Can Not Deny Access to Workload's Own Variables CWE-682 2.7 Low 2023-03-14
CVE-2023-0821 Nomad Client Vulnerable to Decompression Bombs in Artifact Block CWE-409 6.5 Medium 2023-02-16
CVE-2022-3867 Nomad Event Stream Subscriber Using a Token with TTL Receives Updates Until Garbage Collected CWE-613 2.7 Low 2022-11-10
CVE-2022-3866 Nomad Workload Identity Token Can List Non-sensitive Metadata for Paths Under nomad/ CWE-668 5.0 Medium 2022-11-10

All 21 known CVE vulnerabilities affecting Nomad with full Chinese analysis, references, and POCs where available.