H

HashiCorp Security Bulletins

H

HCSEC-2026-24 - Multiple vulnerabilities impacting HashiCorp Consul MCP Server

Bulletin ID: HCSEC-2026-24 Affected Products / Versions: consul-mcp-server 0.1.0 up to 0.1.3; fixed in 0.1.4. Publication Date: July 29, 2026 Summary consul-mcp-server versions 0.1.0 up to 0.1.3 are affected by two vulnerabilities. First, the server did not restrict client-supplied overrides of the Consul backend address, which may allow a connected client to redirect Consul API traffic to an atta…

H

HCSEC-2026-23 - Multiple vulnerabilities impacting HashiCorp Terraform MCP Server

Bulletin ID: HCSEC-2026-23 Affected Products / Versions: terraform-mcp-server 0.2.1 up to and including 1.0.0; fixed in 1.1.0. Publication Date: July 28, 2026 Summary The terraform-mcp-server before version 1.1.0 is vulnerable to three related issues in its streamable-HTTP transport: a server-side request forgery issue that may allow an unauthenticated client to redirect the server’s bearer token…

H
HashiCorp Security Bulletins Security

HCSEC-2026-22 - Nomad vulnerable to cross-namespace host volume claim deletion

Bulletin ID: HCSEC-2026-22 Affected Products / Versions: Nomad and Nomad Enterprise up to 2.0.3; fixed in Nomad 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. Publication Date: July 8, 2026 Summary HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permis…

H
HashiCorp Security Bulletins Security

HCSEC-2026-21 - Nomad vulnerable to sandbox escape in Docker task driver

Bulletin ID: HCSEC-2026-21 Affected Products / Versions: Nomad and Nomad Enterprise up to 2.0.3; fixed in Nomad 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. Publication Date: July 8, 2026 Summary HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind…

H
HashiCorp Security Bulletins Security

HCSEC-2026-20 - Consul-template vulnerable to path redirections in writeToFile

Bulletin ID: HCSEC-2026-20 Affected Products / Versions: Consul-template up to and including 0.42.0; fixed in 0.42.1. Publication Date: July 8, 2026 Summary The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This v…

H
HashiCorp Security Bulletins Security

HCSEC-2026-19 - Nomad Docker driver vulnerable to host namespace bypass on Linux

Bulletin ID: HCSEC-2026-19 Affected Products / Versions: Nomad and Nomad Enterprise up to 2.0.3; fixed in Nomad 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. Publication Date: July 8, 2026 Summary HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver’s host namespace mode options. This may allow an authenticated job submitter to r…

H
HashiCorp Security Bulletins Security

HCSEC-2026-18 - Memberlist vulnerable to denial of service via gossip message

Bulletin ID: HCSEC-2026-18 Affected Products / Versions: memberlist up to 0.5.4; fixed in 0.6.0. Publication Date: July 8, 2026 Summary HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vu…

H
HashiCorp Security Bulletins Security

HCSEC-2026-17 - Terraform Enterprise vulnerable to arbitrary file read

Bulletin ID: HCSEC-2026-17 Affected Products / Versions: Terraform Enterprise v202506-1, v202507-1, and 1.0.0 through 2.0.3; fixed in Terraform Enterprise 2.0.4, 1.2.4. Publication Date: July 6, 2026 Summary HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module cont…

H
HashiCorp Security Bulletins Security

HCSEC-2026-16 - Vault Audit Device Plugin Directory Guard Bypass via Legacy Path Option

Bulletin ID: HCSEC-2026-16 Affected Products / Versions: Vault Community Edition 1.20.1 and later, up to 2.0.0; fixed in 2.0.1, 1.21.6, and 1.20.11. Vault Enterprise 1.19.0 and later, up to 2.0.0; fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17. Publication Date: July 1, 2026 Summary HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin di…

H
HashiCorp Security Bulletins Security

HCSEC-2026-15 - Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution

Bulletin ID: HCSEC-2026-15 Affected Products / Versions: Nomad Community Edition from 1.10.0 up to 2.0.0, fixed in 2.0.1; Nomad Enterprise from 1.10.0 up to 2.0.0, fixed in 2.0.1, 1.11.5, and 1.10.11. Publication Date: May 12, 2026 Summary HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE…

H
HashiCorp Security Bulletins Security

HCSEC-2026-14 - Nomad arbitrary file read/write on client host through symlink attack

Bulletin ID: HCSEC-2026-14 Affected Products / Versions: Nomad Community Edition from 0.9 up to 2.0.0, fixed in 2.0.1; Nomad Enterprise from 0.9 up to 2.0.0, fixed in 2.0.1, 1.11.5, and 1.10.11. Publication Date: May 12, 2026 Summary HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink att…

H
HashiCorp Security Bulletins Security

HCSEC-2026-13 - Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack

Bulletin ID: HCSEC-2026-13 Affected Products / Versions: Nomad exec2 task driver up to 0.1.1; fixed in version 0.1.2. Publication Date: May 12, 2026 Summary HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2…

H
HashiCorp Security Bulletins Security

HCSEC-2026-12 - Consul-template vulnerable to sandbox path bypass in file helper through symlink attack

Bulletin ID: HCSEC-2026-12 Affected Products / Versions: Consul-template up to 0.41.4; fixed in 0.42.0. Publication Date: May 12, 2026 Summary The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0. Background The file te…

H
HashiCorp Security Bulletins Security

HCSEC-2026-11 - Boundary Workers Vulnerable to Denial of Service During TLS Handshake

Bulletin ID: HCSEC-2026-11 Affected Products / Versions: Boundary Community Edition and Boundary Enterprise up to 0.21.2, 0.20.2, 0.19.4, fixed in 0.21.3, 0.20.3, 0.19.5 Publication Date: May 4th, 2026 Summary Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access…

H
HashiCorp Security Bulletins Security

HCSEC-2026-10 - Updates to HashiCorp subprocessors

Bulletin ID: HCSEC-2026-10 Publication Date: April 27, 2026 Summary As part of HashiCorp’s ongoing commitment to privacy and transparency, we have updated our subprocessors list. These updates include details about the following subprocessors: Entity Description Action Taken Products Affected Forethought Customer support and ticket routing Removed All Products DocuSign Document signing software Re…

H
HashiCorp Security Bulletins Security

HCSEC-2026-09 - Remediation and Improved Secret Management for GitHub Webhook Secret Exposure

Bulletin ID: HCSEC-2026-09 Publication Date: April 20, 2026 Target Audience: All HCP Terraform and Terraform Enterprise customers using GitHub integrations for Version Control System (VCS) workflows. Executive Summary On April 15th, GitHub disclosed a security incident involving a bug in their webhook delivery platform. Between September 2025 and January 2026, GitHub inadvertently included webhook…

H
HashiCorp Security Bulletins Security

HCSEC-2026-08 - Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

Bulletin ID: HCSEC-2026-08 Affected Products / Versions: Vault Community Edition up to 1.21.4, fixed in 2.0.0 Vault Enterprise up to 1.21.4, 1.20.9, and 1.19.15; fixed in 2.0.0. Publication Date: April 16th, 2026 Summary Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the s…

H
HashiCorp Security Bulletins Security

HCSEC-2026-07 - Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

Bulletin ID: HCSEC-2026-07 Affected Products / Versions: Vault Community Edition from 0.11.2 up to 1.21.4, fixed in 2.0.0. Vault Enterprise from 0.11.2 up to 1.21.4, 1.20.9, and 1.19.15; fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16. Publication Date: April 16th, 2026 Summary If a Vault auth mount is configured to pass through the “Authorization” header, and the “Authorization” header is used to au…

H
HashiCorp Security Bulletins Security

HCSEC-2026-06 - Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

Bulletin ID: HCSEC-2026-06 Affected Products / Versions: Vault Community Edition 1.14.0 up to 1.21.4, fixed in 2.0.0 Vault Enterprise 1.14.0 up to 1.21.4, 1.20.9, and 1.19.15; fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16. Publication Date: April 16th, 2026 Summary Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to the…

H
HashiCorp Security Bulletins Security

HCSEC-2026-05 - Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service

Bulletin ID: HCSEC-2026-05 Affected Products / Versions: Vault Community Edition 0.10 up to 1.21.4, fixed in 2.0.0 Vault Enterprise 0.10 up to 1.21.4, 1.20.9, and 1.19.15; fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16. Publication Date: April 16th, 2026 Summary An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized…

H
HashiCorp Security Bulletins Security

HCSEC-2026-04 - Go-getter may allow to arbitrary filesystem reads through git operations

Bulletin ID: HCSEC-2026-04 Affected Products / Versions: go-getter up to 1.8.5; fixed in 1.8.6. Publication Date: April 9, 2026 Summary HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go…

H
HashiCorp Security Bulletins Security

HCSEC-2026-03 - HashiCorp GPG Key (72D7468F) Update

Bulletin ID: HCSEC-2026-03 Publication Date: March 12, 2026 Summary This bulletin is for informational purposes only. HashiCorp published signatures can be verified using the same public key as previously, and there should be no external action required. The GPG key for security@hashicorp.com (C874011F0AB405110D02105534365D9472D7468F), used to sign binaries on releases.hashicorp.com, is set to exp…

H
HashiCorp Security Bulletins Security

HCSEC-2026-02 - Consul Vulnerable to Arbitrary File Reads Through the Vault Kubernetes Authentication Provider

Bulletin ID: HCSEC-2026-02 Affected Products / Versions: Consul Community Edition up to 1.22.4, fixed in 1.22.5. Consul Enterprise up to 1.18.20, 1.21.10 and 1.22.4 fixed in 1.18.21, 1.21.11 and 1.22.5. Publication Date: March 11, 2026 Summary HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication…

H
HashiCorp Security Bulletins Security

HCSEC-2026-01 - Arbitrary code execution in React server-side rendering of untrusted MDX content

Bulletin ID: HCSEC-2026-01 Affected Products / Versions: next-mdx-remote from 4.3.0 up to 5.0.0, fixed in 6.0.0. Publication Date: February 11, 2026 Summary The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0. Background next-mdx-…

H
HashiCorp Security Bulletins Security

HCSEC-2025-33 - Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method

Bulletin ID: HCSEC-2025-33 Affected Products / Versions: Vault Terraform Provider from v4.2.0 up to v5.4.0, fixed in v5.5.0. Publication Date: November 21, 2025 Summary Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or un…

H
HashiCorp Security Bulletins Security

HCSEC-2025-34 - Terraform Enterprise state versions can be created by users without sufficient write access

Bulletin ID: HCSEC-2025-34 Affected Products / Versions: Terraform Enterprise up to 1.1.0, and 1.0.2; fixed in Terraform Enterprise 1.1.1, 1.0.3 Publication Date: November 21, 2025 Summary Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operatio…

H
HashiCorp Security Bulletins Security

HCSEC-2025-29 - Consul's KV endpoint is vulnerable to denial of service

Bulletin ID: HCSEC-2025-29 Affected Products / Versions: Consul Community Edition up to 1.21.5, fixed in 1.22.0. Consul Enterprise up to 1.21.5, 1.20.7, 1.19.9 and 1.18.11 fixed in 1.22.0, 1.21.6, 1.20.8 and 1.18.12. Note: Consul Enterprise 1.19 is no longer part of the Long-Term Support (LTS) versions therefore won’t get a fix for this finding. We strongly recommend customers upgrading to a newer…

H
HashiCorp Security Bulletins Security

HCSEC-2025-28 - Consul's event endpoint is vulnerable to denial of service

Bulletin ID: HCSEC-2025-28 Affected Products / Versions: Consul Community Edition up to 1.21.5, fixed in 1.22.0. Consul Enterprise up to 1.21.5, 1.20.7, 1.19.9 and 1.18.11 fixed in 1.22.0, 1.21.6, 1.20.8 and 1.18.12. Note: Consul Enterprise 1.19 is no longer part of the Long-Term Support (LTS) versions therefore won’t get a fix for this finding. We strongly recommend customers upgrading to a newer…

H
HashiCorp Security Bulletins Security

HCSEC-2025-32 - Incomplete Fix For Previous Vault DoS Issue

Bulletin ID: HCSEC-2025-32 Affected Products / Versions: Vault Community Edition 1.20.3 to 1.20.4; fixed in 1.21.0. Vault Enterprise 1.20.3 to 1.20.4, 1.19.9 to 1.19.10, 1.18.14 to 1.18.15, 1.16.25 to 1.16.26; fixed in 1.21.0, 1.20.5, 1.19.11, and 1.16.27 Publication Date: October 23, 2025 Summary A fix for a previous security issue impacting HashiCorp Vault (HCSEC-2025-24 / CVE-2025-6203) was inc…

H
HashiCorp Security Bulletins Security

HCSEC-2025-31- Vault Vulnerable to Denial of Service Due to Rate Limit Regression

Bulletin ID: HCSEC-2025-31 Affected Products / Versions: Vault Community Edition 1.20.3 to 1.20.4; fixed in 1.21.0. Vault Enterprise 1.20.3 to 1.20.4, 1.19.9 to 1.19.10, 1.18.14 to 1.18.15, 1.16.25 to 1.16.26; fixed in 1.21.0, 1.20.5, 1.19.11, and 1.16.27 Publication Date: October 23, 2025 Summary Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when proc…