Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

HashiCorp — Vulnerabilities & Security Advisories 119

Browse all 119 CVE security advisories affecting HashiCorp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HashiCorp develops infrastructure automation software, primarily known for Terraform, Vault, and Consul, which enable organizations to provision and secure cloud infrastructure. The company’s products have historically been associated with various vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation, often stemming from complex integration points or misconfigurations in how these tools interact with underlying systems. With 89 CVEs currently on record, the security landscape for HashiCorp tools reflects the inherent risks of widely adopted, high-privilege infrastructure management software. While no single catastrophic incident has defined the brand’s history, the volume of disclosed flaws highlights the challenges of maintaining security across a diverse ecosystem of plugins and integrations. Users must rigorously patch these tools to mitigate risks associated with unauthorized access or data exfiltration, ensuring that the powerful automation capabilities do not become vectors for systemic compromise.

CVE ID Title CVSS Severity Published
CVE-2026-5006 Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths — Vault CWE-639 6.8 Medium 2026-08-24
CVE-2026-14978 Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions — go-slug CWE-176 5.5 Medium 2026-08-19
CVE-2026-19589 Packer vulnerable to arbitrary file write via crafted plugin archive during installation — Packer CWE-22 7.1 High 2026-08-17
CVE-2026-8715 Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath — Tooling CWE-552 9.6 Critical 2026-08-13
CVE-2026-14886 Vault Enterprise vulnerable to cross-namespace entity deletion — Vault Enterprise CWE-862 8.2 High 2026-08-10
CVE-2026-12624 Vault vulnerable to LIST authorization bypass via trailing-slash strip — Vault CWE-863 4.3 Medium 2026-08-10
CVE-2026-19113 Unauthenticated denial of service via unbounded request body processing — Consul CWE-400 5.3 Medium 2026-08-07
CVE-2026-15972 Unauthenticated denial of service via unbounded external gRPC connection acceptance — Consul CWE-770 7.5 High 2026-08-07
CVE-2026-15970 L7 intention authorization bypass via custom public listener — Consul CWE-647 4.2 Medium 2026-08-07
CVE-2026-19017 Consul vulnerable to partial arbitrary file read via Vault Connect CA provider — Consul CWE-862 6.8 Medium 2026-08-07
CVE-2026-19015 Uncontrolled resource consumption in the Consul Connect CA roots endpoint — Consul CWE-770 5.3 Medium 2026-08-07
CVE-2026-19014 Uncontrolled resource consumption in the Consul Connect authorization endpoint — Consul CWE-770 4.3 Medium 2026-08-07
CVE-2026-19012 Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path — Consul CWE-476 5.3 Medium 2026-08-07
CVE-2026-19016 Authorization bypass for session deletion in the transaction API — Consul CWE-22 4.2 Medium 2026-08-07
CVE-2026-16326 consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode — Tooling CWE-488 10.0 Critical 2026-07-29
CVE-2026-16328 consul-mcp-server vulnerable to server side request forgery leading to token exposure — Tooling CWE-918 8.6 High 2026-07-29
CVE-2026-16498 terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode — Tooling CWE-488 10.0 Critical 2026-07-28
CVE-2026-16496 terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user — Tooling CWE-384 8.9 High 2026-07-28
CVE-2026-14869 terraform-mcp-server vulnerable to server side request forgery leading to token exposure — Tooling CWE-918 8.6 High 2026-07-28
CVE-2026-14896 Nomad vulnerable to cross-namespace host volume claim deletion — Nomad CWE-863 4.2 Medium 2026-07-08
CVE-2026-14361 Consul-template is vulnerable to path redirection in writeToFile through symlink attack — Tooling CWE-59 4.7 Medium 2026-07-08
CVE-2026-14891 Nomad vulnerable to sandbox escape in Docker task driver — Nomad CWE-59 8.7 High 2026-07-08
CVE-2026-14373 Nomad Docker driver Linux host namespace bypass — Nomad CWE-862 7.7 High 2026-07-08
CVE-2026-14362 Denial of service via crafted push/pull gossip message in memberlist — Shared library CWE-770 4.9 Medium 2026-07-08
CVE-2026-14468 Path traversal allows arbitrary file read in Terraform Enterprise container — Terraform Enterprise CWE-22 7.7 High 2026-07-06
CVE-2026-5051 Audit Log Plugin Directory Guard Bypass via Legacy path Option — Vault CWE-22 4.4 Medium 2026-07-01
CVE-2026-7474 Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution — Nomad CWE-22 8.8 High 2026-05-12
CVE-2026-8052 Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack — Shared library CWE-59 6.0 Medium 2026-05-12
CVE-2026-6959 Nomad vulnerable to arbitrary file read/write on client host through symlink attack — Nomad CWE-59 6.0 Medium 2026-05-12
CVE-2026-5061 Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack — Tooling CWE-59 4.7 Medium 2026-05-12

This page lists every published CVE security advisory associated with HashiCorp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.