|
HCSEC-2026-22 - Nomad vulnerable to cross-namespace host volume claim deletion
|
|
0
|
107
|
July 8, 2026
|
|
HCSEC-2026-21 - Nomad vulnerable to sandbox escape in Docker task driver
|
|
0
|
122
|
July 8, 2026
|
|
HCSEC-2026-19 - Nomad Docker driver vulnerable to host namespace bypass on Linux
|
|
0
|
107
|
July 8, 2026
|
|
HCSEC-2026-18 - Memberlist vulnerable to denial of service via gossip message
|
|
0
|
118
|
July 8, 2026
|
|
HCSEC-2026-15 - Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution
|
|
0
|
409
|
May 12, 2026
|
|
HCSEC-2026-14 - Nomad arbitrary file read/write on client host through symlink attack
|
|
0
|
193
|
May 12, 2026
|
|
HCSEC-2026-13 - Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack
|
|
0
|
216
|
May 12, 2026
|
|
HCSEC-2025-12 - Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job
|
|
0
|
949
|
June 11, 2025
|
|
HCSEC-2025-08 - Nomad Enterprise Vulnerable To Violation Of Mandatory Sentinel Policies in Job Submissions via Policy Override
|
|
0
|
682
|
May 13, 2025
|
|
HCSEC-2025-04 - Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs
|
|
0
|
763
|
March 10, 2025
|
|
HCSEC-2025-02 - Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace
|
|
0
|
647
|
February 12, 2025
|
|
HCSEC-2024-29 - Nomad Allocations Vulnerable To Privilege Escalation Within A Namespace Using Unredacted Workload Identity Token
|
|
0
|
665
|
December 20, 2024
|
|
HCSEC-2024-27 - Nomad Vulnerable To Cross-Namespace Volume Creation Abusing CSI Write Permission
|
|
0
|
900
|
November 7, 2024
|
|
HCSEC-2023-21 - Nomad Caller ACL Token's Secret ID is Exposed to Sentinel
|
|
0
|
5704
|
July 19, 2023
|
|
HCSEC-2024-17 - Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking
|
|
0
|
1431
|
August 14, 2024
|
|
HCSEC-2024-15 - Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking
|
|
0
|
1397
|
July 22, 2024
|
|
HCSEC-2024-03 - Nomad Vulnerable to Arbitrary Write Through Symlink Attack
|
|
0
|
6638
|
February 8, 2024
|
|
HCSEC-2023-22 - Nomad Search API Leaks Information About CSI Plugins
|
|
0
|
5837
|
July 19, 2023
|
|
HCSEC-2023-20 - Nomad ACL Policies without Label are Applied to Unexpected Resources
|
|
0
|
5911
|
July 19, 2023
|
|
HCSEC-2021-01 - Nomad’s Exec and Java Task Drivers Did Not Isolate Processes
|
|
0
|
7392
|
January 29, 2021
|
|
HCSEC-2023-09 - Nomad ACLs Can Not Deny Access to Workload's Own Variables
|
|
0
|
5345
|
March 13, 2023
|
|
HCSEC-2023-08 - Nomad Job Submitter Privilege Escalation Using Workload Identity
|
|
0
|
5379
|
March 13, 2023
|
|
HCSEC-2022-25 - Nomad’s Workload Identity Token Can List Non-sensitive Metadata For nomad/ Paths
|
|
0
|
6007
|
October 28, 2022
|
|
HCSEC-2022-26 - Nomad’s Event Stream Subscriber Using ACL Token with TTL Receive Updates Until Garbage Collected
|
|
0
|
5949
|
October 28, 2022
|
|
HCSEC-2022-22 - Nomad Panics On Job Submission With Bad Artifact Stanza Source URL
|
|
0
|
5906
|
October 10, 2022
|
|
HCSEC-2022-14 - Nomad Impacted by go-getter Vulnerabilities
|
|
0
|
6965
|
May 24, 2022
|
|
HCSEC-2022-04 - Nomad Spread Job Stanza May Trigger Panic in Servers
|
|
0
|
7618
|
February 11, 2022
|
|
HCSEC-2022-03 - Nomad Malformed Job Parsing Results in Excessive CPU Usage
|
|
0
|
7251
|
February 11, 2022
|
|
HCSEC-2022-02 - Nomad alloc Filesystem and Container Escape
|
|
0
|
7328
|
February 11, 2022
|
|
HCSEC-2022-01 - Nomad Artifact Download Race Condition
|
|
0
|
7556
|
February 11, 2022
|