VulnSea

HashiCorp has 32 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 6 in the last 90 days against 4 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.2 (high). None have a confirmed exploitation report. Most affected products: github.com/hashicorp/vault (15), github.com/hashicorp/consul (9), Consul (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.2
Publish → KEV
Last 90 days
6 prev 4

Products

  • github.com/hashicorp/vault 15
  • github.com/hashicorp/consul 9
  • Consul 4
  • Shared library 1
  • Tooling 1
  • github.com/hashicorp/boundary 1
32
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

hashicorp vulnerabilities

CVEs affecting hashicorp, newest first. Open any entry for full detail, references, and exploit status.

32 CVEsRSS

CVE-2026-88922Medium· 6.7
1w ago

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…

SunlitHashiCorp · Shared libraryEPSS 0.09%via NVD
CVE-2026-87993High· 7.7
1w ago

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…

TwilightHashiCorp · ToolingEPSS 0.27%via NVD
CVE-2026-87090High· 8.3
1w ago

Consul vulnerable to an authorization bypass in the catalog node-write path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker wit…

TwilightHashiCorp · ConsulEPSS 0.21%via CVEORG
CVE-2026-87106Medium· 6.5
1w ago

Consul vulnerable to a denial of service in the native RPC listener

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal …

SunlitHashiCorp · ConsulEPSS 0.24%via CVEORG
CVE-2026-88021High· 7.5
1w ago

Consul vulnerable to an authorization bypass in the Connect service mesh

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentio…

TwilightHashiCorp · ConsulEPSS 0.24%via CVEORG
CVE-2026-87107Medium· 5.4
1w ago

Consul vulnerable to an authorization bypass in the catalog deregistration path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permiss…

SunlitHashiCorp · ConsulEPSS 0.23%via CVEORG
CVE-2026-7776High· 7.5
4mo ago

Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes

Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes

Twilighthashicorp · github.com/hashicorp/boundaryEPSS 0.20%via OSV
CVE-2026-5052Medium· 5.3
5mo ago

HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.34%via OSV
CVE-2026-5807High· 7.5
5mo ago

HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.72%via OSV
CVE-2026-4525High· 7.5
5mo ago

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.41%via OSV
CVE-2025-11374Medium· 6.5
10mo ago

Consul key/value endpoint is vulnerable to denial of service

Consul key/value endpoint is vulnerable to denial of service

Sunlithashicorp · github.com/hashicorp/consulEPSS 0.40%via OSV
CVE-2025-6013Medium· 6.5
1y ago

HashiCorp Vault ldap auth method may not have correctly enforced MFA

HashiCorp Vault ldap auth method may not have correctly enforced MFA

Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.50%via OSV
CVE-2025-5999High· 7.2
1y ago

Hashicorp Vault has Privilege Escalation Vulnerability

Hashicorp Vault has Privilege Escalation Vulnerability

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.51%via OSV
CVE-2025-6037Medium· 6.8
1y ago

Hashicorp Vault has Incorrect Validation for Non-CA Certificates

Hashicorp Vault has Incorrect Validation for Non-CA Certificates

Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.25%via OSV
CVE-2025-4166Medium· 4.5
1y ago

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.43%via OSV
CVE-2024-8185High· 7.5
1y ago

Hashicorp Vault vulnerable to denial of service through memory exhaustion

Hashicorp Vault vulnerable to denial of service through memory exhaustion

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.48%via OSV
CVE-2024-9180High· 7.2
1y ago

Vault Community Edition privilege escalation vulnerability

Vault Community Edition privilege escalation vulnerability

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.53%via OSV
CVE-2024-7594High· 7.5
1y ago

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.27%via OSV
CVE-2024-6468High· 7.5
2y ago

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.49%via OSV
CVE-2024-5798Low· 2.6
2y ago

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.34%via OSV
CVE-2023-5954High· 7.5
2y ago

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.72%via OSV
CVE-2023-5077High· 7.6
2y ago

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.44%via OSV
CVE-2023-4680Medium· 6.8
3y ago

HashiCorp Vault Improper Input Validation vulnerability

HashiCorp Vault Improper Input Validation vulnerability

Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.44%via OSV
CVE-2023-3518High· 7.4
3y ago

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers

Twilighthashicorp · github.com/hashicorp/consulEPSS 0.45%via OSV
CVE-2023-0845Medium· 6.5
3y ago

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections

Sunlithashicorp · github.com/hashicorp/consulEPSS 1.0%via OSV
CVE-2022-3920High· 7.5
3y ago

Missing Authorization in HashiCorp Consul

Missing Authorization in HashiCorp Consul

Twilighthashicorp · github.com/hashicorp/consulEPSS 0.70%via OSV
CVE-2021-41803High· 7.1
3y ago

HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions

HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions

Twilighthashicorp · github.com/hashicorp/consulEPSS 1.1%via OSV
CVE-2020-8567Medium· 4.9
4y ago

Kubernetes Secrets Store CSI Driver plugins arbitrary file write

Kubernetes Secrets Store CSI Driver plugins arbitrary file write

Sunlithashicorp · github.com/hashicorp/vault-csi-providerEPSS 1.4%via OSV
CVE-2018-19653Medium· 5.9
4y ago

HashiCorp Consul can use cleartext agent-to-agent RPC communication

HashiCorp Consul can use cleartext agent-to-agent RPC communication

Sunlithashicorp · github.com/hashicorp/consulEPSS 1.2%via OSV
CVE-2021-38698Medium· 6.5
5y ago

HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…

HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.

Sunlithashicorp · github.com/hashicorp/consulEPSS 1.4%via OSV
hashicorp vulnerabilities (CVEs) · VulnSea