Hashicorp Security Vulnerabilities (CVEs)
Track 52 security vulnerabilities affecting Hashicorp products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
The Vault Terraform Provider incorrectly set the deny_null_bind parameter to false by default for LDAP authentication, potentially allowing authentica...
Nov 21, 2025In Terraform Enterprise, users with specific but insufficient permissions can create state versions in workspaces, potentially allowing infrastructure...
Nov 21, 2025Consul's key/value endpoint is vulnerable to denial of service due to incorrect Content Length header validation. Attackers can send malformed request...
Oct 28, 2025Consul's event endpoint is vulnerable to denial of service (DoS) attacks due to lack of validation on Content-Length headers, allowing attackers to se...
Oct 28, 2025Vault and Vault Enterprise are vulnerable to unauthenticated denial of service attacks when processing JSON payloads due to a regression in rate limit...
Oct 23, 2025This vulnerability allows authentication bypass in HashiCorp Vault's AWS Auth method when the bound_principal_iam role is identical across AWS account...
Oct 23, 2025CVE-2025-6203 is a denial-of-service vulnerability in HashiCorp Vault where specially crafted JSON payloads can cause excessive memory and CPU consump...
Aug 28, 2025CVE-2025-8959 is a symlink attack vulnerability in HashiCorp's go-getter library that allows attackers to read files outside the intended download dir...
Aug 15, 2025This vulnerability allows attackers to bypass multi-factor authentication (MFA) rate limiting and reuse TOTP tokens in HashiCorp Vault, potentially en...
Aug 1, 2025The Vault TLS certificate authentication method fails to properly validate client certificates when configured with non-CA certificates as trusted cer...
Aug 1, 2025A privileged Vault operator with write permissions to the root namespace's identity endpoint can escalate token privileges to Vault's root policy, gra...
Aug 1, 2025A privileged Vault operator with write permission to the sys/audit endpoint can execute arbitrary code on the underlying host when Vault is configured...
Aug 1, 2025The Vault TOTP secrets engine code validation endpoint allows time-based one-time password codes to be reused within their validity period. This affec...
Aug 1, 2025This vulnerability in Nomad's ACL policy lookup system can cause incorrect rule application and shadowing, potentially allowing unauthorized access to...
Jun 11, 2025CVE-2025-4166 allows sensitive information exposure in Vault server and audit logs when users submit malformed payloads during secret creation or upda...
May 2, 2025Nomad audit logs unintentionally expose sensitive workload identity tokens and client secret tokens. This allows attackers with access to audit logs t...
Mar 10, 2025CVE-2025-1293 is an authentication bypass vulnerability in Hermes versions up to 0.4.0 that improperly validates AWS ALB JWTs, potentially allowing un...
Feb 20, 2025This vulnerability allows attackers to bypass ACL policies in Nomad event streams configured with wildcard namespaces, enabling unauthorized read acce...
Feb 12, 2025HashiCorp's go-slug library is vulnerable to a zip-slip attack when extracting tar archives with non-existing user-provided paths. This allows attacke...
Jan 21, 2025This vulnerability allows attackers to cause denial-of-service through memory exhaustion by sending excessive requests to Vault's Raft cluster join AP...
Oct 31, 2024This vulnerability allows a Vault operator with write permissions to the root namespace's identity endpoint to escalate their own or another user's pr...
Oct 10, 2024This vulnerability allows an attacker with access to a Nomad client agent to write files outside the intended allocation directory during archive unpa...
Aug 15, 2024This vulnerability allows attackers to escape the intended directory structure during archive unpacking in Nomad migrations, potentially writing files...
Jul 23, 2024CVE-2024-6257 is a vulnerability in HashiCorp's go-getter library where an attacker can manipulate Git configuration files to execute arbitrary code d...
Jun 25, 2024CVE-2024-6104 is an information disclosure vulnerability in go-retryablehttp where URLs containing HTTP basic authentication credentials are written t...
Jun 24, 2024HashiCorp's go-getter library is vulnerable to argument injection when executing Git commands to discover remote branches. This allows attackers to in...
Apr 17, 2024Boundary and Boundary Enterprise are vulnerable to session hijacking through TLS certificate tampering. Attackers with specific privileges can craft T...
Feb 5, 2024HashiCorp Vault versions 1.12.0 and newer are vulnerable to denial of service through memory exhaustion when processing large HTTP requests. Attackers...
Dec 8, 2023This vulnerability in HashiCorp Vault's Google Cloud secrets engine removes existing IAM Conditions when creating or updating rolesets, potentially gr...
Sep 29, 2023This vulnerability allows users with service:write permissions in Consul to modify Envoy proxy configurations for downstream services they don't own. ...
Jun 2, 2023This vulnerability allows unauthenticated users to bypass ACL (Access Control List) authorizations in HashiCorp Nomad clusters where mTLS (mutual TLS)...
Apr 5, 2023This vulnerability in HashiCorp Vault's PKI mount allows unauthorized users to delete or modify PKI issuer metadata, potentially causing denial of ser...
Mar 30, 2023This vulnerability in HashiCorp Nomad allows job submitters to escalate privileges to management-level access using workload identity and task API fea...
Mar 14, 2023HashiCorp Vault Enterprise clusters using Integrated Storage expose an unauthenticated API endpoint that allows attackers to override a node's voter s...
Jul 26, 2022This vulnerability in HashiCorp Nomad and Nomad Enterprise allows attackers to escalate privileges on client agent hosts by exploiting go-getter vulne...
Jun 2, 2022This vulnerability in the go-getter library allows attackers to bypass security controls, switch protocols, and create endless redirects by manipulati...
May 25, 2022This vulnerability in the go-getter library allows attackers to perform path traversal, symlink processing, and command injection attacks, potentially...
May 25, 2022This vulnerability in go-getter library causes a panic (crash) when processing password-protected ZIP files. It affects applications using go-getter u...
May 25, 2022CVE-2021-44139 is a Server-Side Request Forgery (SSRF) vulnerability in Sentinel 1.8.2 that allows attackers to make unauthorized requests from the vu...
Mar 23, 2022This vulnerability in HashiCorp Nomad allows attackers to submit specially crafted HCL job configurations to the jobs parse endpoint, causing excessiv...
Feb 28, 2022HashiCorp Terraform Enterprise versions v202112-1 through v202201-2 log inbound HTTP requests in a way that may capture sensitive data like credential...
Feb 25, 2022This vulnerability allows operators with read-fs and alloc-exec (or job-submit) capabilities in HashiCorp Nomad to read arbitrary files on the host fi...
Feb 17, 2022This vulnerability allows authenticated users with job submission capabilities in HashiCorp Nomad to bypass configured allowed image paths when using ...
Dec 3, 2021This vulnerability allows non-server agents in HashiCorp Nomad clusters to access server-only Raft RPC functionality, enabling privilege escalation. A...
Sep 7, 2021This vulnerability in HashiCorp Consul's Envoy proxy allows TLS connections to bypass service identity validation. Attackers could potentially interce...
Jul 17, 2021HashiCorp Vault and Vault Enterprise had a vulnerability where tokens or dynamic secret leases within 1 second of expiration could be renewed and inco...
Jun 3, 2021HashiCorp Vault's Cassandra integrations failed to validate TLS certificates when connecting to Cassandra clusters, allowing man-in-the-middle attacks...
Apr 22, 2021This vulnerability in HashiCorp Terraform's Vault Provider incorrectly configures GCE-type bound labels for Vault's GCP authentication method, potenti...
Apr 22, 2021This vulnerability allows attackers to bypass audit logging in HashiCorp Consul Enterprise by sending specifically crafted HTTP events. This affects C...
Apr 20, 2021HashiCorp Vault Enterprise versions 1.6.0 and 1.6.1 allow unauthenticated execution of the 'remove-peer' raft operator command on DR (Disaster Recover...
Feb 1, 2021Why Monitor Hashicorp Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 52+ known vulnerabilities affecting Hashicorp products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Hashicorp packages in under 60 seconds. No agents required - completely agentless scanning that works across Hashicorp deployments.
Free vulnerability database: Access detailed information about every Hashicorp CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Hashicorp CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions