|
About HashiCorp security updates
|
|
0
|
13549
|
October 8, 2020
|
|
HCSEC-2026-39 - Go-getter vulnerable to a privilege escalation issue in its archive decompression handling
|
|
0
|
142
|
September 15, 2026
|
|
HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling
|
|
0
|
173
|
September 10, 2026
|
|
HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh
|
|
0
|
179
|
September 10, 2026
|
|
HCSEC-2026-36 - Consul vulnerable to an authorization bypass in the catalog deregistration path
|
|
0
|
138
|
September 10, 2026
|
|
HCSEC-2026-35 - Consul vulnerable to a denial of service in the native RPC listener
|
|
0
|
144
|
September 10, 2026
|
|
HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path
|
|
0
|
195
|
September 10, 2026
|
|
HCSEC-2026-33 - HashiCorp Linux Signing GPG Key Update (CA026560)
|
|
0
|
1371
|
September 10, 2026
|
|
HCSEC-2026-32 - Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
|
|
0
|
489
|
August 24, 2026
|
|
HCSEC-2026-31 - Go-slug vulnerable to exclusion bypass in .terraformignore handling
|
|
0
|
157
|
August 20, 2026
|
|
HCSEC-2026-30 - Updates to HashiCorp subprocessors
|
|
0
|
75
|
August 18, 2026
|
|
HCSEC-2026-29 - Packer vulnerable to arbitrary file write via crafted plugin archive during installation
|
|
0
|
169
|
August 17, 2026
|
|
HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath
|
|
0
|
769
|
August 13, 2026
|
|
HCSEC-2026-27 - Vault Enterprise vulnerable to cross-namespace entity deletion
|
|
0
|
539
|
August 10, 2026
|
|
HCSEC-2026-26 - Vault vulnerable to LIST authorization bypass via trailing-slash strip
|
|
0
|
355
|
August 10, 2026
|
|
HCSEC-2026-25 - Multiple vulnerabilities impacting HashiCorp Consul
|
|
0
|
466
|
August 7, 2026
|
|
HCSEC-2026-24 - Multiple vulnerabilities impacting HashiCorp Consul MCP Server
|
|
0
|
337
|
July 29, 2026
|
|
HCSEC-2026-23 - Multiple vulnerabilities impacting HashiCorp Terraform MCP Server
|
|
0
|
998
|
July 28, 2026
|
|
HCSEC-2026-22 - Nomad vulnerable to cross-namespace host volume claim deletion
|
|
0
|
223
|
July 8, 2026
|
|
HCSEC-2026-21 - Nomad vulnerable to sandbox escape in Docker task driver
|
|
0
|
244
|
July 8, 2026
|
|
HCSEC-2026-20 - Consul-template vulnerable to path redirections in writeToFile
|
|
0
|
184
|
July 8, 2026
|
|
HCSEC-2026-19 - Nomad Docker driver vulnerable to host namespace bypass on Linux
|
|
0
|
202
|
July 8, 2026
|
|
HCSEC-2026-18 - Memberlist vulnerable to denial of service via gossip message
|
|
0
|
224
|
July 8, 2026
|
|
HCSEC-2026-17 - Terraform Enterprise vulnerable to arbitrary file read
|
|
0
|
567
|
July 6, 2026
|
|
HCSEC-2026-16 - Vault Audit Device Plugin Directory Guard Bypass via Legacy Path Option
|
|
0
|
396
|
July 1, 2026
|
|
HCSEC-2026-15 - Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution
|
|
0
|
496
|
May 12, 2026
|
|
HCSEC-2026-14 - Nomad arbitrary file read/write on client host through symlink attack
|
|
0
|
227
|
May 12, 2026
|
|
HCSEC-2026-13 - Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack
|
|
0
|
271
|
May 12, 2026
|
|
HCSEC-2026-12 - Consul-template vulnerable to sandbox path bypass in file helper through symlink attack
|
|
0
|
273
|
May 12, 2026
|
|
HCSEC-2026-11 - Boundary Workers Vulnerable to Denial of Service During TLS Handshake
|
|
0
|
343
|
May 4, 2026
|