📦 Nomad

by Hashicorp

🔍 What is Nomad?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-1782

CRITICAL CVSS 9.9 Apr 5, 2023

This vulnerability allows unauthenticated users to bypass ACL (Access Control List) authorizations in HashiCorp Nomad clusters where mTLS (mutual TLS) is not enabled. Attackers can escalate privileges...

CVE-2022-30324

CRITICAL CVSS 9.8 Jun 2, 2022

This vulnerability in HashiCorp Nomad and Nomad Enterprise allows attackers to escalate privileges on client agent hosts by exploiting go-getter vulnerabilities through the artifact stanza in submitte...

CVE-2020-27195

CRITICAL CVSS 9.1 Oct 22, 2020

This vulnerability allows attackers to bypass the file sandbox feature in HashiCorp Nomad clients using template or artifact stanzas, potentially leading to arbitrary file access or code execution. It...

CVE-2025-4922

HIGH CVSS 8.1 Jun 11, 2025

This vulnerability in Nomad's ACL policy lookup system can cause incorrect rule application and shadowing, potentially allowing unauthorized access to resources. It affects Nomad Community and Enterpr...

CVE-2025-0937

HIGH CVSS 7.1 Feb 12, 2025

This vulnerability allows attackers to bypass ACL policies in Nomad event streams configured with wildcard namespaces, enabling unauthorized read access to other namespaces. It affects Nomad Community...

CVE-2024-6717

HIGH CVSS 7.7 Jul 23, 2024

This vulnerability allows attackers to escape the intended directory structure during archive unpacking in Nomad migrations, potentially writing files to arbitrary locations on the host filesystem. It...

CVE-2023-1299

HIGH CVSS 7.4 Mar 14, 2023

This vulnerability in HashiCorp Nomad allows job submitters to escalate privileges to management-level access using workload identity and task API features. It affects organizations running Nomad or N...

CVE-2022-24685

HIGH CVSS 7.5 Feb 28, 2022

This vulnerability in HashiCorp Nomad allows attackers to submit specially crafted HCL job configurations to the jobs parse endpoint, causing excessive CPU consumption and potential denial of service....

CVE-2022-24683

HIGH CVSS 7.5 Feb 17, 2022

This vulnerability allows operators with read-fs and alloc-exec (or job-submit) capabilities in HashiCorp Nomad to read arbitrary files on the host filesystem as root. This affects Nomad and Nomad Ent...

CVE-2021-43415

HIGH CVSS 8.8 Dec 3, 2021

This vulnerability allows authenticated users with job submission capabilities in HashiCorp Nomad to bypass configured allowed image paths when using the QEMU task driver. Attackers could execute arbi...

CVE-2021-37218

HIGH CVSS 8.8 Sep 7, 2021

This vulnerability allows non-server agents in HashiCorp Nomad clusters to access server-only Raft RPC functionality, enabling privilege escalation. Any Nomad deployment using TLS certificates signed ...

CVE-2025-1296

MEDIUM CVSS 6.5 Mar 10, 2025

Nomad audit logs unintentionally expose sensitive workload identity tokens and client secret tokens. This allows attackers with access to audit logs to impersonate workloads or clients. Affects Nomad ...

CVE-2024-7625

MEDIUM CVSS 5.8 Aug 15, 2024

This vulnerability allows an attacker with access to a Nomad client agent to write files outside the intended allocation directory during archive unpacking. It affects HashiCorp Nomad and Nomad Enterp...