H

HashiCorp Security Bulletins

H

HCSEC-2026-39 - Go-getter vulnerable to a privilege escalation issue in its archive decompression handling

Bulletin ID: HCSEC-2026-39 Affected Products / Versions: Go-getter up to 1.8.8 and 2.2.3; fixed in go-getter 1.8.9 and 2.2.4 Publication Date: September 15, 2026 Summary The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permiss…

H

HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling

Bulletin ID: HCSEC-2026-38 Affected Products / Versions: consul-template 0.27.2 through 0.42.1; fixed in consul-template 0.43.0 Publication Date: September 10, 2026 Summary The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad…

H

HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh

Bulletin ID: HCSEC-2026-37 Affected Products / Versions: Consul and Consul Enterprise 1.9.0 through 2.0.3; fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. Publication Date: September 10, 2026 Summary Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to acce…

H

HCSEC-2026-36 - Consul vulnerable to an authorization bypass in the catalog deregistration path

Bulletin ID: HCSEC-2026-36 Affected Products / Versions: Consul and Consul Enterprise 1.21.0 through 2.0.3; fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. Publication Date: September 10, 2026 Summary Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog obj…

H

HCSEC-2026-35 - Consul vulnerable to a denial of service in the native RPC listener

Bulletin ID: HCSEC-2026-35 Affected Products / Versions: Consul and Consul Enterprise 1.21.0 through 2.0.3; fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. Publication Date: September 10, 2026 Summary Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL autho…

H

HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path

Bulletin ID: HCSEC-2026-34 Affected Products / Versions: Consul and Consul Enterprise up to 2.0.3; fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4. Publication Date: September 10, 2026 Summary Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node’s catalog registr…

H

HCSEC-2026-33 - HashiCorp Linux Signing GPG Key Update (CA026560)

Bulletin ID: HCSEC-2026-33 Publication Date: September 10, 2026 Summary This bulletin is for informational purposes only. The HashiCorp GPG key used to sign Linux packages was rotated on September 10th, 2026. The new key fingerprint is D55C 0D1A C78A 8D81 26CB 631C FC9C A96A CA02 6560. The new key fingerprint is also available on our Trust Page (https://www.hashicorp.com/en/trust/security). We dee…

H
HashiCorp Security Bulletins Security

HCSEC-2026-32 - Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths

Bulletin ID: HCSEC-2026-32 Affected Products / Versions: Vault Community Edition from 0.11.0 up to 2.0.3; fixed in 2.0.4. Vault Enterprise from 0.11.0 up to 2.0.3, 1.21.8, 1.20.13, and 1.19.19; fixed in 2.0.4, 1.21.9, 1.20.14, and 1.19.20. Publication Date: August 24, 2026 Summary A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker m…

H
HashiCorp Security Bulletins Security

HCSEC-2026-31 - Go-slug vulnerable to exclusion bypass in .terraformignore handling

Bulletin ID: HCSEC-2026-31 Affected Products / Versions: github.com/hashicorp/go-slug v0.4.0 through v0.18.2; fixed in v0.18.3. Publication Date: August 20, 2026 Summary The github.com/hashicorp/go-slug library before v0.18.3 is vulnerable to an exclusion bypass in .terraformignore handling that may allow files intended to be excluded from Terraform Cloud or Terraform Enterprise working directory…

H
HashiCorp Security Bulletins Security

HCSEC-2026-30 - Updates to HashiCorp subprocessors

Bulletin ID: HCSEC-2026-30 Publication Date: August 18, 2026 Summary As part of HashiCorp’s ongoing commitment to privacy and transparency, we have updated our subprocessors list. These updates include details about the following subprocessors: Entity Description Action Taken Products Affected NetSuite Billing and accounting Removed All Products Replicated Installation and packaging Removed Terraf…

H
HashiCorp Security Bulletins Security

HCSEC-2026-29 - Packer vulnerable to arbitrary file write via crafted plugin archive during installation

Bulletin ID: HCSEC-2026-29 Affected Products / Versions: Packer 1.7.0 up to 1.15.4; fixed in Packer 1.16.0 Publication Date: August 17, 2026 Summary Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected.…

H
HashiCorp Security Bulletins Security

HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath

Bulletin ID: HCSEC-2026-28 Affected Products / Versions: Vault Secrets Operator 1.3.0 up to 1.4.1; fixed in Vault Secrets Operator 1.5.0. Publication Date: August 13, 2026 Summary Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissi…

H
HashiCorp Security Bulletins Security

HCSEC-2026-27 - Vault Enterprise vulnerable to cross-namespace entity deletion

Bulletin ID: HCSEC-2026-27 Affected Products / Versions: Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16 LTS, up to 2.0.3, 1.21.8, 1.20.13, and 1.19.19 LTS; fixed in Vault Enterprise 2.0.4, 1.21.9, 1.20.14 and 1.19.20. Publication Date: August 10, 2026 Summary Vault Enterprise’s identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an aut…

H
HashiCorp Security Bulletins Security

HCSEC-2026-26 - Vault vulnerable to LIST authorization bypass via trailing-slash strip

Bulletin ID: HCSEC-2026-26 Affected Products / Versions: Vault and Vault Enterprise up to 2.0.2; fixed in Vault 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19 Publication Date: August 10, 2026 Summary Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding…

H
HashiCorp Security Bulletins Security

HCSEC-2026-25 - Multiple vulnerabilities impacting HashiCorp Consul

Bulletin ID: HCSEC-2026-25 Affected Products / Versions: CVE-2026-19012: Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2. CVE-2026-19014: Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2. CVE-2026-19015: Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2. CVE-2026-19017: Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2. CVE…

H
HashiCorp Security Bulletins Security

HCSEC-2026-24 - Multiple vulnerabilities impacting HashiCorp Consul MCP Server

Bulletin ID: HCSEC-2026-24 Affected Products / Versions: consul-mcp-server 0.1.0 up to 0.1.3; fixed in 0.1.4. Publication Date: July 29, 2026 Summary consul-mcp-server versions 0.1.0 up to 0.1.3 are affected by two vulnerabilities. First, the server did not restrict client-supplied overrides of the Consul backend address, which may allow a connected client to redirect Consul API traffic to an atta…

H
HashiCorp Security Bulletins Security

HCSEC-2026-23 - Multiple vulnerabilities impacting HashiCorp Terraform MCP Server

Bulletin ID: HCSEC-2026-23 Affected Products / Versions: terraform-mcp-server 0.2.1 up to and including 1.0.0; fixed in 1.1.0. Publication Date: July 28, 2026 Summary The terraform-mcp-server before version 1.1.0 is vulnerable to three related issues in its streamable-HTTP transport: a server-side request forgery issue that may allow an unauthenticated client to redirect the server’s bearer token…

H
HashiCorp Security Bulletins Security

HCSEC-2026-22 - Nomad vulnerable to cross-namespace host volume claim deletion

Bulletin ID: HCSEC-2026-22 Affected Products / Versions: Nomad and Nomad Enterprise up to 2.0.3; fixed in Nomad 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. Publication Date: July 8, 2026 Summary HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permis…

H
HashiCorp Security Bulletins Security

HCSEC-2026-21 - Nomad vulnerable to sandbox escape in Docker task driver

Bulletin ID: HCSEC-2026-21 Affected Products / Versions: Nomad and Nomad Enterprise up to 2.0.3; fixed in Nomad 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. Publication Date: July 8, 2026 Summary HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind…

H
HashiCorp Security Bulletins Security

HCSEC-2026-20 - Consul-template vulnerable to path redirections in writeToFile

Bulletin ID: HCSEC-2026-20 Affected Products / Versions: Consul-template up to and including 0.42.0; fixed in 0.42.1. Publication Date: July 8, 2026 Summary The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This v…

H
HashiCorp Security Bulletins Security

HCSEC-2026-19 - Nomad Docker driver vulnerable to host namespace bypass on Linux

Bulletin ID: HCSEC-2026-19 Affected Products / Versions: Nomad and Nomad Enterprise up to 2.0.3; fixed in Nomad 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. Publication Date: July 8, 2026 Summary HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver’s host namespace mode options. This may allow an authenticated job submitter to r…

H
HashiCorp Security Bulletins Security

HCSEC-2026-18 - Memberlist vulnerable to denial of service via gossip message

Bulletin ID: HCSEC-2026-18 Affected Products / Versions: memberlist up to 0.5.4; fixed in 0.6.0. Publication Date: July 8, 2026 Summary HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vu…

H
HashiCorp Security Bulletins Security

HCSEC-2026-17 - Terraform Enterprise vulnerable to arbitrary file read

Bulletin ID: HCSEC-2026-17 Affected Products / Versions: Terraform Enterprise v202506-1, v202507-1, and 1.0.0 through 2.0.3; fixed in Terraform Enterprise 2.0.4, 1.2.4. Publication Date: July 6, 2026 Summary HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module cont…

H
HashiCorp Security Bulletins Security

HCSEC-2026-16 - Vault Audit Device Plugin Directory Guard Bypass via Legacy Path Option

Bulletin ID: HCSEC-2026-16 Affected Products / Versions: Vault Community Edition 1.20.1 and later, up to 2.0.0; fixed in 2.0.1, 1.21.6, and 1.20.11. Vault Enterprise 1.19.0 and later, up to 2.0.0; fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17. Publication Date: July 1, 2026 Summary HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin di…

H
HashiCorp Security Bulletins Security

HCSEC-2026-15 - Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution

Bulletin ID: HCSEC-2026-15 Affected Products / Versions: Nomad Community Edition from 1.10.0 up to 2.0.0, fixed in 2.0.1; Nomad Enterprise from 1.10.0 up to 2.0.0, fixed in 2.0.1, 1.11.5, and 1.10.11. Publication Date: May 12, 2026 Summary HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE…

H
HashiCorp Security Bulletins Security

HCSEC-2026-14 - Nomad arbitrary file read/write on client host through symlink attack

Bulletin ID: HCSEC-2026-14 Affected Products / Versions: Nomad Community Edition from 0.9 up to 2.0.0, fixed in 2.0.1; Nomad Enterprise from 0.9 up to 2.0.0, fixed in 2.0.1, 1.11.5, and 1.10.11. Publication Date: May 12, 2026 Summary HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink att…

H
HashiCorp Security Bulletins Security

HCSEC-2026-13 - Nomad's exec2 task driver vulnerable to arbitrary file read/write on client host through symlink attack

Bulletin ID: HCSEC-2026-13 Affected Products / Versions: Nomad exec2 task driver up to 0.1.1; fixed in version 0.1.2. Publication Date: May 12, 2026 Summary HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2…

H
HashiCorp Security Bulletins Security

HCSEC-2026-12 - Consul-template vulnerable to sandbox path bypass in file helper through symlink attack

Bulletin ID: HCSEC-2026-12 Affected Products / Versions: Consul-template up to 0.41.4; fixed in 0.42.0. Publication Date: May 12, 2026 Summary The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0. Background The file te…

H
HashiCorp Security Bulletins Security

HCSEC-2026-11 - Boundary Workers Vulnerable to Denial of Service During TLS Handshake

Bulletin ID: HCSEC-2026-11 Affected Products / Versions: Boundary Community Edition and Boundary Enterprise up to 0.21.2, 0.20.2, 0.19.4, fixed in 0.21.3, 0.20.3, 0.19.5 Publication Date: May 4th, 2026 Summary Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access…

H
HashiCorp Security Bulletins Security

HCSEC-2026-10 - Updates to HashiCorp subprocessors

Bulletin ID: HCSEC-2026-10 Publication Date: April 27, 2026 Summary As part of HashiCorp’s ongoing commitment to privacy and transparency, we have updated our subprocessors list. These updates include details about the following subprocessors: Entity Description Action Taken Products Affected Forethought Customer support and ticket routing Removed All Products DocuSign Document signing software Re…