Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

HashiCorp — Vulnerabilities & Security Advisories 118

Browse all 118 CVE security advisories affecting HashiCorp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

HashiCorp develops infrastructure automation software, primarily known for Terraform, Vault, and Consul, which enable organizations to provision and secure cloud infrastructure. The company’s products have historically been associated with various vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation, often stemming from complex integration points or misconfigurations in how these tools interact with underlying systems. With 89 CVEs currently on record, the security landscape for HashiCorp tools reflects the inherent risks of widely adopted, high-privilege infrastructure management software. While no single catastrophic incident has defined the brand’s history, the volume of disclosed flaws highlights the challenges of maintaining security across a diverse ecosystem of plugins and integrations. Users must rigorously patch these tools to mitigate risks associated with unauthorized access or data exfiltration, ensuring that the powerful automation capabilities do not become vectors for systemic compromise.

CVE ID Title CVSS Severity Published
CVE-2026-5807 Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations — Vault CWE-770 7.5 High 2026-04-17
CVE-2026-4525 Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header — Vault CWE-201 7.5 High 2026-04-17
CVE-2026-5052 Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS — Vault CWE-918 5.3 Medium 2026-04-17
CVE-2026-3605 Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service — Vault CWE-288 8.1 High 2026-04-17
CVE-2026-4660 Go-getter may allow to arbitrary filesystem reads through git operations — Tooling CWE-200 7.5 High 2026-04-09
CVE-2026-2808 Consul vulnerable to arbitrary file reads through the vault kubernetes authentication provider — Consul CWE-59 6.8 Medium 2026-03-11
CVE-2026-0969 Arbitrary code execution in React server-side rendering of untrusted MDX content — Shared library CWE-94 8.8 High 2026-02-12
CVE-2025-13357 Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method — Tooling CWE-1188 7.4 High 2025-11-21
CVE-2025-13432 Terraform Enterprise state versions can be created by users with specific permissions without sufficient write access — Terraform Enterprise CWE-863 4.3 Medium 2025-11-21
CVE-2025-11374 Consul's KV endpoint is vulnerable to denial of service — Consul CWE-770 6.5 Medium 2025-10-28
CVE-2025-11375 Consul's event endpoint is vulnerable to denial of service — Consul CWE-770 6.5 Medium 2025-10-28
CVE-2025-12044 Vault Vulnerable to Denial of Service Due to Rate Limit Regression — Vault CWE-770 7.5 High 2025-10-23
CVE-2025-11621 Vault AWS auth method bypass due to AWS client cache — Vault CWE-288 8.1 High 2025-10-23
CVE-2025-6203 Vault unauthenticated denial of service through complex json payload — Vault CWE-770 7.5 High 2025-08-28
CVE-2025-8959 HashiCorp go-getter Vulnerable to Arbitrary Read through Symlink Attack — Shared library CWE-59 7.5 High 2025-08-15
CVE-2025-6013 Vault LDAP MFA Enforcement Bypass When Using Username As Alias — Vault CWE-156 6.5 Medium 2025-08-06
CVE-2025-6015 Vault Login MFA Bypass of Rate Limiting and TOTP Code Reuse — Vault CWE-307 5.7 Medium 2025-08-01
CVE-2025-6011 Timing Side-Channel in Vault’s Userpass Auth Method — Vault CWE-203 3.7 Low 2025-08-01
CVE-2025-6004 Vault Userpass and LDAP User Lockout Bypass — Vault CWE-307 5.3 Medium 2025-08-01
CVE-2025-6037 Vault Certificate Auth Method Did Not Validate Common Name For Non-CA Certificates — Vault CWE-295 6.8 Medium 2025-08-01
CVE-2025-6014 Vault TOTP Secrets Engine Code Reuse — Vault CWE-156 6.5 Medium 2025-08-01
CVE-2025-6000 Arbitrary Remote Code Execution via Plugin Catalog Abuse — Vault CWE-94 9.1 Critical 2025-08-01
CVE-2025-5999 Vault Root Namespace Operator May Elevate Token Privileges — Vault CWE-266 7.2 High 2025-08-01
CVE-2025-4656 Vault Vulnerable to Recovery Key Cancellation Denial of Service — Vault CWE-1088 3.1 Low 2025-06-25
CVE-2025-4922 Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job — Nomad CWE-266 8.1 High 2025-06-11
CVE-2025-3744 Nomad Vulnerable To Violation Of Mandatory Sentinel Policies in Nomad Job Submissions via Policy Override — Nomad Enterprise CWE-266 7.6 High 2025-05-13
CVE-2025-3879 Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login — Vault CWE-863 6.6 Medium 2025-05-02
CVE-2025-4166 Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin — Vault CWE-209 4.5 Medium 2025-05-02
CVE-2025-1296 Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs — Nomad CWE-532 6.5 Medium 2025-03-10
CVE-2025-1293 HashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication Bypass — Tooling CWE-1390 8.2 High 2025-02-20

This page lists every published CVE security advisory associated with HashiCorp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.