CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “hashicorp”

189 vulnerabilities found for “hashicorp”

Page 1 of 10

CVE-2025-1293
HIGH8.2

Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.

hashicorp / hermes
Adjacent
Published Feb 20, 2025
Page 1 of 10
CVE-2024-6104
MEDIUM6.0

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

hashicorp / retryablehttp
Local
Published Jun 24, 2024
CVE-2023-5834
LOW3.8

HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.

hashicorp / vagrant
Local
Published Oct 27, 2023
CVE-2022-3866
MEDIUM5.0

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.

hashicorp / nomad+3
Network
Published Nov 10, 2022
CVE-2022-41606
MEDIUM6.5

HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.

hashicorp / nomad+3
Network
Published Oct 12, 2022
CVE-2022-42717
HIGH7.8

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

hashicorp / vagrant
Local
Published Oct 11, 2022
CVE-2022-30324
CRITICAL9.8

HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

hashicorp / nomad+5
Network
Published Jun 2, 2022
CVE-2022-24685
HIGH7.5

HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.

hashicorp / nomad+5
Network
Published Feb 28, 2022
CVE-2022-24683
HIGH7.5

HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

hashicorp / nomad+5
Network
Published Feb 17, 2022
CVE-2022-24684
MEDIUM6.5

HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to panic server agents. Fixed in 1.0.18, 1.1.12, and 1.2.6.

hashicorp / nomad+5
Network
Published Feb 15, 2022
CVE-2022-24686
MEDIUM5.9

HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6

hashicorp / nomad+5
Network
Published Feb 14, 2022
CVE-2021-43415
HIGH8.8

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

hashicorp / nomad+5
Network
Published Dec 3, 2021
CVE-2021-41865
MEDIUM6.5

HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.

hashicorp / nomad+1
Network
Published Oct 7, 2021
CVE-2021-37218
HIGH8.8

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

hashicorp / nomad+3
Network
Published Sep 7, 2021
CVE-2021-32575
MEDIUM6.5

HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.

hashicorp / nomad+1
Adjacent
Published Jun 17, 2021
CVE-2021-32074
HIGH7.5

HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.

hashicorp / vault-action
Network
Published May 7, 2021
CVE-2021-3283
HIGH7.5

HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.

hashicorp / nomad+3
Network
Published Feb 1, 2021
CVE-2020-28348
MEDIUM6.5

HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8.

hashicorp / nomad+5
Network
Published Nov 24, 2020
CVE-2020-27195
CRITICAL9.1

HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6

hashicorp / nomad+5
Network
Published Oct 22, 2020
CVE-2020-10944
MEDIUM5.4

HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.

hashicorp / nomad+1
Network
Published Apr 28, 2020