Vulnerabilidades em HashiCorp

125 resultados
Análise Vexday

Com 93 CVEs catalogadas e nenhuma registrada no CISA KEV, o perfil de risco ativo da HashiCorp situa-se abaixo da média geral do catálogo, indicando ausência de exploração confirmada em campo até o momento. As 3 vulnerabilidades de severidade crítica e as 10 surgidas nos últimos 90 dias merecem acompanhamento próximo, especialmente CVE-2026-7474, que concentra o maior escore EPSS observado no portfólio (0,0689) e representa o vetor de maior probabilidade de exploração a curto prazo. A falha mais recorrente por tipo é CWE-266 (controle incorreto de privilégios), o que sugere atenção às configurações de permissão e ao modelo de confiança em ambientes que utilizam ferramentas HashiCorp para gestão de credenciais e infraestrutura. A ausência de PoCs públicas conhecidas reduz a superfície de ataque imediata, mas não elimina a necessidade de aplicar correções com regularidade, dado o ritmo recente de novas descobertas.

CVE-2026-14891HIGHNomad vulnerable to sandbox escape in Docker task driverEPSS 0.5%CVE-2024-8185HIGHVault Vulnerable to Denial of Service When Processing Raft Join RequestsEPSS 0.5%CVE-2026-2808MEDIUMConsul vulnerable to arbitrary file reads through the vault kubernetes authentication providerEPSS 0.5%CVE-2024-10006HIGHConsul L7 Intentions Vulnerable To Headers BypassEPSS 0.5%CVE-2026-16498CRITICALterraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless modeEPSS 0.5%CVE-2024-8365MEDIUMVault Leaks AppRole Client Tokens And Accessor in Audit LogEPSS 0.5%CVE-2023-0475MEDIUMGo-Getter Vulnerable to Decompression BombsEPSS 0.5%CVE-2023-3775MEDIUMVault Enterprise's Sentinel RGP Policies Allowed For Cross-Namespace Denial of ServiceEPSS 0.5%CVE-2024-10975HIGHNomad Vulnerable To Cross-Namespace Volume Creation Abusing CSI Write PermissionEPSS 0.4%CVE-2024-2048HIGHVault Cert Auth Method Did Not Correctly Validate Non-CA CertificatesEPSS 0.4%CVE-2023-3518HIGHJWT Auth in L7 Intentions Allow For Mismatched Service Identity and JWT Providers for AccessEPSS 0.4%CVE-2025-0937HIGHNomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard NamespaceEPSS 0.4%CVE-2026-14468HIGHPath traversal allows arbitrary file read in Terraform Enterprise containerEPSS 0.4%CVE-2023-4680MEDIUMVault's Transit Secrets Engine Allowed Nonce Specified without Convergent EncryptionEPSS 0.4%CVE-2026-14362MEDIUMDenial of service via crafted push/pull gossip message in memberlistEPSS 0.4%CVE-2023-0690MEDIUMBoundary Workers Store Rotated Credentials in Plaintext Even When a Key Management Service ConfiguredEPSS 0.4%CVE-2023-5077HIGHVault's Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating RolesetsEPSS 0.4%CVE-2023-3072MEDIUMNomad ACL Policies without Label are Applied to Unexpected ResourcesEPSS 0.4%CVE-2025-4166MEDIUMVault May Include Sensitive Data in Error Logs When Using the KV v2 PluginEPSS 0.4%CVE-2023-3114MEDIUMTerraform Enterprise Agent Pool Controls Allowed Unauthorized Workspaces To Target an Agent PoolEPSS 0.4%