Vulnerabilities in HashiCorp

125 results
Vexday analysis

Com 93 CVEs catalogadas e nenhuma registrada no CISA KEV, o perfil de risco ativo da HashiCorp situa-se abaixo da média geral do catálogo, indicando ausência de exploração confirmada em campo até o momento. As 3 vulnerabilidades de severidade crítica e as 10 surgidas nos últimos 90 dias merecem acompanhamento próximo, especialmente CVE-2026-7474, que concentra o maior escore EPSS observado no portfólio (0,0689) e representa o vetor de maior probabilidade de exploração a curto prazo. A falha mais recorrente por tipo é CWE-266 (controle incorreto de privilégios), o que sugere atenção às configurações de permissão e ao modelo de confiança em ambientes que utilizam ferramentas HashiCorp para gestão de credenciais e infraestrutura. A ausência de PoCs públicas conhecidas reduz a superfície de ataque imediata, mas não elimina a necessidade de aplicar correções com regularidade, dado o ritmo recente de novas descobertas.

CVE-2023-4680MEDIUMVault's Transit Secrets Engine Allowed Nonce Specified without Convergent EncryptionEPSS 0.4%CVE-2023-0690MEDIUMBoundary Workers Store Rotated Credentials in Plaintext Even When a Key Management Service ConfiguredEPSS 0.4%CVE-2023-3072MEDIUMNomad ACL Policies without Label are Applied to Unexpected ResourcesEPSS 0.4%CVE-2023-5077HIGHVault's Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating RolesetsEPSS 0.4%CVE-2025-4166MEDIUMVault May Include Sensitive Data in Error Logs When Using the KV v2 PluginEPSS 0.4%CVE-2023-3114MEDIUMTerraform Enterprise Agent Pool Controls Allowed Unauthorized Workspaces To Target an Agent PoolEPSS 0.4%CVE-2025-3879MEDIUMVault’s Azure Authentication Method bound_location Restriction Could be Bypassed on LoginEPSS 0.4%CVE-2024-10086MEDIUMConsul Vulnerable To Reflected XSS On Content-Type Error ManipulationEPSS 0.4%CVE-2023-2121MEDIUMVault’s KV Diff Viewer Allowed for HTML InjectionEPSS 0.4%CVE-2025-6004MEDIUMVault Userpass and LDAP User Lockout BypassEPSS 0.4%CVE-2026-87106MEDIUMConsul vulnerable to a denial of service in the native RPC listenerEPSS 0.4%CVE-2026-19015MEDIUMUncontrolled resource consumption in the Consul Connect CA roots endpointEPSS 0.4%CVE-2026-19113MEDIUMUnauthenticated denial of service via unbounded request body processingEPSS 0.4%CVE-2025-11374MEDIUMConsul's KV endpoint is vulnerable to denial of serviceEPSS 0.4%CVE-2025-11375MEDIUMConsul's event endpoint is vulnerable to denial of serviceEPSS 0.4%CVE-2026-14869HIGHterraform-mcp-server vulnerable to server side request forgery leading to token exposureEPSS 0.4%CVE-2026-16328HIGHconsul-mcp-server vulnerable to server side request forgery leading to token exposureEPSS 0.4%CVE-2024-12289MEDIUMBoundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of ServiceEPSS 0.4%CVE-2025-6014MEDIUMVault TOTP Secrets Engine Code ReuseEPSS 0.4%CVE-2024-6717HIGHNomad Vulnerable to Allocation Directory Path Escape Through Archive UnpackingEPSS 0.4%