|
About HashiCorp security updates
|
|
0
|
13475
|
October 8, 2020
|
|
HCSEC-2026-32 - Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
|
|
0
|
305
|
August 24, 2026
|
|
HCSEC-2026-31 - Go-slug vulnerable to exclusion bypass in .terraformignore handling
|
|
0
|
109
|
August 20, 2026
|
|
HCSEC-2026-30 - Updates to HashiCorp subprocessors
|
|
0
|
58
|
August 18, 2026
|
|
HCSEC-2026-29 - Packer vulnerable to arbitrary file write via crafted plugin archive during installation
|
|
0
|
116
|
August 17, 2026
|
|
HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath
|
|
0
|
674
|
August 13, 2026
|
|
HCSEC-2026-27 - Vault Enterprise vulnerable to cross-namespace entity deletion
|
|
0
|
476
|
August 10, 2026
|
|
HCSEC-2026-26 - Vault vulnerable to LIST authorization bypass via trailing-slash strip
|
|
0
|
296
|
August 10, 2026
|
|
HCSEC-2026-25 - Multiple vulnerabilities impacting HashiCorp Consul
|
|
0
|
374
|
August 7, 2026
|
|
HCSEC-2026-24 - Multiple vulnerabilities impacting HashiCorp Consul MCP Server
|
|
0
|
302
|
July 29, 2026
|
|
HCSEC-2026-23 - Multiple vulnerabilities impacting HashiCorp Terraform MCP Server
|
|
0
|
943
|
July 28, 2026
|
|
HCSEC-2026-22 - Nomad vulnerable to cross-namespace host volume claim deletion
|
|
0
|
194
|
July 8, 2026
|
|
HCSEC-2026-21 - Nomad vulnerable to sandbox escape in Docker task driver
|
|
0
|
211
|
July 8, 2026
|
|
HCSEC-2026-20 - Consul-template vulnerable to path redirections in writeToFile
|
|
0
|
161
|
July 8, 2026
|
|
HCSEC-2026-19 - Nomad Docker driver vulnerable to host namespace bypass on Linux
|
|
0
|
178
|
July 8, 2026
|
|
HCSEC-2026-18 - Memberlist vulnerable to denial of service via gossip message
|
|
0
|
196
|
July 8, 2026
|
|
HCSEC-2026-17 - Terraform Enterprise vulnerable to arbitrary file read
|
|
0
|
520
|
July 6, 2026
|
|
HCSEC-2026-16 - Vault Audit Device Plugin Directory Guard Bypass via Legacy Path Option
|
|
0
|
347
|
July 1, 2026
|
|
HCSEC-2026-15 - Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution
|
|
0
|
467
|
May 12, 2026
|
|
HCSEC-2026-14 - Nomad arbitrary file read/write on client host through symlink attack
|
|
0
|
212
|
May 12, 2026
|
|
HCSEC-2026-13 - Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack
|
|
0
|
244
|
May 12, 2026
|
|
HCSEC-2026-12 - Consul-template vulnerable to sandbox path bypass in file helper through symlink attack
|
|
0
|
254
|
May 12, 2026
|
|
HCSEC-2026-11 - Boundary Workers Vulnerable to Denial of Service During TLS Handshake
|
|
0
|
325
|
May 4, 2026
|
|
HCSEC-2026-10 - Updates to HashiCorp subprocessors
|
|
0
|
98
|
April 27, 2026
|
|
HCSEC-2026-09 - Remediation and Improved Secret Management for GitHub Webhook Secret Exposure
|
|
0
|
463
|
April 20, 2026
|
|
HCSEC-2026-08 - Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
|
|
0
|
1032
|
April 17, 2026
|
|
HCSEC-2026-07 - Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
|
|
0
|
774
|
April 17, 2026
|
|
HCSEC-2026-06 - Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
|
|
0
|
757
|
April 17, 2026
|
|
HCSEC-2026-05 - Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service
|
|
0
|
1028
|
April 17, 2026
|
|
HCSEC-2026-04 - Go-getter may allow to arbitrary filesystem reads through git operations
|
|
0
|
398
|
April 9, 2026
|