---
id: CVE-2026-87993
title: >-
  The consul-template library is vulnerable to an information disclosure issue
  in its error handling path that may allow Vault secret values to appear in
  template error messages, log output, and downstream surfaces such as Nomad
  task event…
summary: >-
  The consul-template library is vulnerable to an information disclosure issue
  in its error handling path that may allow Vault secret values to appear in
  template error messages, log output, and downstream surfaces such as Nomad
  task event…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-532
vendor: HashiCorp
product: Tooling
affected:
  - Tooling >= 0.27.2 < 0.43.0
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T20:17:31.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87993'
references:
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2026-38-consul-template-vulnerable-to-an-information-disclosure-issue-in-error-handling/77740
    label: security@hashicorp.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T19:21:10.302684Z'
ingestedAt: '2026-09-13T19:53:19.580Z'
epss: 0.00275
epssPercentile: 0.20123
---

## Overview

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
