HashiCorp has 32 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 6 in the last 90 days against 4 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.2 (high). None have a confirmed exploitation report. Most affected products: github.com/hashicorp/vault (15), github.com/hashicorp/consul (9), Consul (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 6 prev 4
Products
- github.com/hashicorp/vault 15
- github.com/hashicorp/consul 9
- Consul 4
- Shared library 1
- Tooling 1
- github.com/hashicorp/boundary 1
Worst active — by depth score
CVE-2026-87090High· 8.3Consul vulnerable to an authorization bypass in the catalog node-write path46CVE-2026-87993High· 7.7The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…42CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability42CVE-2021-32574High· 7.5Hashicorp Consul Missing SSL Certificate Validation42CVE-2020-7219High· 7.5Denial of Service (DoS) in HashiCorp Consul42
hashicorp vulnerabilities
CVEs affecting hashicorp, newest first. Open any entry for full detail, references, and exploit status.
32 CVEsRSS
CVE-2026-88922Medium· 6.7The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…
The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…
CVE-2026-87993High· 7.7The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…
The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…
CVE-2026-87090High· 8.3Consul vulnerable to an authorization bypass in the catalog node-write path
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker wit…
CVE-2026-87106Medium· 6.5Consul vulnerable to a denial of service in the native RPC listener
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal …
CVE-2026-88021High· 7.5Consul vulnerable to an authorization bypass in the Connect service mesh
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentio…
CVE-2026-87107Medium· 5.4Consul vulnerable to an authorization bypass in the catalog deregistration path
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permiss…
CVE-2026-7776High· 7.5Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
CVE-2026-5052Medium· 5.3HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
CVE-2026-5807High· 7.5HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
CVE-2026-4525High· 7.5HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
CVE-2025-11374Medium· 6.5Consul key/value endpoint is vulnerable to denial of service
Consul key/value endpoint is vulnerable to denial of service
CVE-2025-6013Medium· 6.5HashiCorp Vault ldap auth method may not have correctly enforced MFA
HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-5999High· 7.2Hashicorp Vault has Privilege Escalation Vulnerability
Hashicorp Vault has Privilege Escalation Vulnerability
CVE-2025-6037Medium· 6.8Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
CVE-2025-4166Medium· 4.5Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2024-8185High· 7.5Hashicorp Vault vulnerable to denial of service through memory exhaustion
Hashicorp Vault vulnerable to denial of service through memory exhaustion
CVE-2024-9180High· 7.2Vault Community Edition privilege escalation vulnerability
Vault Community Edition privilege escalation vulnerability
CVE-2024-7594High· 7.5Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
CVE-2024-6468High· 7.5Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
CVE-2024-5798Low· 2.6HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
CVE-2023-5954High· 7.5HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-4680Medium· 6.8HashiCorp Vault Improper Input Validation vulnerability
HashiCorp Vault Improper Input Validation vulnerability
CVE-2023-3518High· 7.4Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
CVE-2023-0845Medium· 6.5Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
CVE-2022-3920High· 7.5Missing Authorization in HashiCorp Consul
Missing Authorization in HashiCorp Consul
CVE-2021-41803High· 7.1HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
CVE-2020-8567Medium· 4.9Kubernetes Secrets Store CSI Driver plugins arbitrary file write
Kubernetes Secrets Store CSI Driver plugins arbitrary file write
CVE-2018-19653Medium· 5.9HashiCorp Consul can use cleartext agent-to-agent RPC communication
HashiCorp Consul can use cleartext agent-to-agent RPC communication
CVE-2021-38698Medium· 6.5HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.