Vulnerabilities in HashiCorp

125 results
Vexday analysis

Com 93 CVEs catalogadas e nenhuma registrada no CISA KEV, o perfil de risco ativo da HashiCorp situa-se abaixo da média geral do catálogo, indicando ausência de exploração confirmada em campo até o momento. As 3 vulnerabilidades de severidade crítica e as 10 surgidas nos últimos 90 dias merecem acompanhamento próximo, especialmente CVE-2026-7474, que concentra o maior escore EPSS observado no portfólio (0,0689) e representa o vetor de maior probabilidade de exploração a curto prazo. A falha mais recorrente por tipo é CWE-266 (controle incorreto de privilégios), o que sugere atenção às configurações de permissão e ao modelo de confiança em ambientes que utilizam ferramentas HashiCorp para gestão de credenciais e infraestrutura. A ausência de PoCs públicas conhecidas reduz a superfície de ataque imediata, mas não elimina a necessidade de aplicar correções com regularidade, dado o ritmo recente de novas descobertas.

CVE-2023-24999MEDIUMVault Fails to Verify if the AppRole SecretID Belongs to Role During a Destroy OperationEPSS 0.6%CVE-2026-0969HIGHArbitrary code execution in React server-side rendering of untrusted MDX contentEPSS 0.6%CVE-2026-4525HIGHVault Token Leaked to Backends via Authorization: Bearer Passthrough HeaderEPSS 0.6%CVE-2023-2816HIGHConsul Envoy Extension Downsteam Proxy Configuration By Upstream Service OwnerEPSS 0.6%CVE-2023-3300MEDIUMNomad Search API Leaks Information About CSI PluginsEPSS 0.6%CVE-2026-15972HIGHUnauthenticated denial of service via unbounded external gRPC connection acceptanceEPSS 0.5%CVE-2026-4660HIGHGo-getter may allow to arbitrary filesystem reads through git operationsEPSS 0.5%CVE-2025-8959HIGHHashiCorp go-getter Vulnerable to Arbitrary Read through Symlink AttackEPSS 0.5%CVE-2026-2808MEDIUMConsul vulnerable to arbitrary file reads through the vault kubernetes authentication providerEPSS 0.5%CVE-2023-1296LOWNomad ACLs Can Not Deny Access to Workload's Own VariablesEPSS 0.5%CVE-2022-3866MEDIUMNomad Workload Identity Token Can List Non-sensitive Metadata for Paths Under nomad/EPSS 0.5%CVE-2024-12678MEDIUMNomad Allocations Vulnerable To Privilege Escalation Within A Namespace Using Unredacted Workload Identity TokensEPSS 0.5%CVE-2026-16326CRITICALconsul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless modeEPSS 0.5%CVE-2023-1299HIGHNomad Job Submitter Privilege Escalation Using Workload IdentityEPSS 0.5%CVE-2025-12044HIGHVault Vulnerable to Denial of Service Due to Rate Limit RegressionEPSS 0.5%CVE-2025-13357HIGHVault Terraform Provider Applied Incorrect Defaults for LDAP Auth MethodEPSS 0.5%CVE-2024-9180HIGHVault Operators in Root Namespace May Elevate Their PrivilegesEPSS 0.5%CVE-2025-4922HIGHNomad Vulnerable To Incorrect ACL Policy Lookup Attached To A JobEPSS 0.5%CVE-2025-5999HIGHVault Root Namespace Operator May Elevate Token PrivilegesEPSS 0.5%CVE-2026-3605HIGHVault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-ServiceEPSS 0.5%