|
About HashiCorp security updates
|
|
0
|
13412
|
October 8, 2020
|
|
HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath
|
|
0
|
41
|
August 13, 2026
|
|
HCSEC-2026-27 - Vault Enterprise vulnerable to cross-namespace entity deletion
|
|
0
|
271
|
August 10, 2026
|
|
HCSEC-2026-26 - Vault vulnerable to LIST authorization bypass via trailing-slash strip
|
|
0
|
152
|
August 10, 2026
|
|
HCSEC-2026-25 - Multiple vulnerabilities impacting HashiCorp Consul
|
|
0
|
212
|
August 7, 2026
|
|
HCSEC-2026-24 - Multiple vulnerabilities impacting HashiCorp Consul MCP Server
|
|
0
|
235
|
July 29, 2026
|
|
HCSEC-2026-23 - Multiple vulnerabilities impacting HashiCorp Terraform MCP Server
|
|
0
|
815
|
July 28, 2026
|
|
HCSEC-2026-22 - Nomad vulnerable to cross-namespace host volume claim deletion
|
|
0
|
159
|
July 8, 2026
|
|
HCSEC-2026-21 - Nomad vulnerable to sandbox escape in Docker task driver
|
|
0
|
168
|
July 8, 2026
|
|
HCSEC-2026-20 - Consul-template vulnerable to path redirections in writeToFile
|
|
0
|
143
|
July 8, 2026
|
|
HCSEC-2026-19 - Nomad Docker driver vulnerable to host namespace bypass on Linux
|
|
0
|
151
|
July 8, 2026
|
|
HCSEC-2026-18 - Memberlist vulnerable to denial of service via gossip message
|
|
0
|
176
|
July 8, 2026
|
|
HCSEC-2026-17 - Terraform Enterprise vulnerable to arbitrary file read
|
|
0
|
479
|
July 6, 2026
|
|
HCSEC-2026-16 - Vault Audit Device Plugin Directory Guard Bypass via Legacy Path Option
|
|
0
|
315
|
July 1, 2026
|
|
HCSEC-2026-15 - Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution
|
|
0
|
451
|
May 12, 2026
|
|
HCSEC-2026-14 - Nomad arbitrary file read/write on client host through symlink attack
|
|
0
|
200
|
May 12, 2026
|
|
HCSEC-2026-13 - Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack
|
|
0
|
235
|
May 12, 2026
|
|
HCSEC-2026-12 - Consul-template vulnerable to sandbox path bypass in file helper through symlink attack
|
|
0
|
242
|
May 12, 2026
|
|
HCSEC-2026-11 - Boundary Workers Vulnerable to Denial of Service During TLS Handshake
|
|
0
|
306
|
May 4, 2026
|
|
HCSEC-2026-10 - Updates to HashiCorp subprocessors
|
|
0
|
82
|
April 27, 2026
|
|
HCSEC-2026-09 - Remediation and Improved Secret Management for GitHub Webhook Secret Exposure
|
|
0
|
438
|
April 20, 2026
|
|
HCSEC-2026-08 - Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
|
|
0
|
983
|
April 17, 2026
|
|
HCSEC-2026-07 - Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
|
|
0
|
725
|
April 17, 2026
|
|
HCSEC-2026-06 - Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
|
|
0
|
710
|
April 17, 2026
|
|
HCSEC-2026-05 - Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service
|
|
0
|
996
|
April 17, 2026
|
|
HCSEC-2026-04 - Go-getter may allow to arbitrary filesystem reads through git operations
|
|
0
|
381
|
April 9, 2026
|
|
HCSEC-2026-03 - HashiCorp GPG Key (72D7468F) Update
|
|
0
|
2545
|
March 12, 2026
|
|
HCSEC-2026-02 - Consul Vulnerable to Arbitrary File Reads Through the Vault Kubernetes Authentication Provider
|
|
0
|
473
|
March 11, 2026
|
|
HCSEC-2026-01 - Arbitrary code execution in React server-side rendering of untrusted MDX content
|
|
0
|
8515
|
February 12, 2026
|
|
HCSEC-2025-33 - Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method
|
|
0
|
1463
|
November 21, 2025
|