Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-5807
Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rek…
Vault
2.0.0+
HIGH 8.6
CVE-2026-5052
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests be…
Vault
1.19.16 / 1.20.10+
HIGH 8.8
CVE-2026-4525
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vaul…
Vault
1.19.16 / 1.20.10+
HIGH 8.1
CVE-2026-3605
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or…
Vault
1.19.16 / 1.20.10+
CRITICAL 9.8
CVE-2025-13357
Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting i…
Terraform Provider
5.5.0+
MEDIUM 6.5
CVE-2025-11374
Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validati…
Consul
1.18.12 / 1.20.8+
MEDIUM 6.5
CVE-2025-11375
Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length …
Consul
1.18.12 / 1.20.8+
HIGH 7.5
CVE-2025-12044
Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regre…
Vault
1.16.27 / 1.20.5+
HIGH 8.1
CVE-2025-11621
Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam …
Vault
1.16.27 / 1.19.11+
HIGH 7.5
CVE-2025-6203
A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory…
Vault
1.16.27 / 1.18.15+
HIGH 7.5
CVE-2025-8959
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designate…
Go Getter
1.7.9+
HIGH 8.1
CVE-2025-6013
Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multi…
Vault
1.16.24 / 1.18.13+
MEDIUM 6.8
CVE-2025-6037
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi…
Vault
1.16.23 / 1.18.12+
MEDIUM 5.7
CVE-2025-6015
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20…
Vault
1.16.23 / 1.18.12+
CRITICAL 9.1
CVE-2025-6000
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a pl…
Vault
1.16.23 / 1.18.12+
HIGH 7.2
CVE-2025-5999
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privile…
Vault
1.16.22 / 1.18.11+
MEDIUM 6.5
CVE-2025-6014
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in…
Vault
1.16.23 / 1.18.12+
MEDIUM 5.3
CVE-2025-6004
Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community …
Vault
1.16.23 / 1.18.12+
HIGH 8.1
CVE-2025-4922
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerabilit…
Nomad
1.8.14 / 1.9.10+
HIGH 7.6
CVE-2025-3744
Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE…
Nomad
1.8.13 / 1.9.9+
HIGH 8.8
CVE-2025-3879
Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the poten…
Vault
1.16.18 / 1.17.14+
MEDIUM 6.5
CVE-2025-4166
Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when u…
Vault
1.16.20 / 1.17.16+
MEDIUM 6.5
CVE-2025-1296
Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in aud…
Nomad
1.7.19 / 1.8.11+
HIGH 8.2
CVE-2025-1293
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication…
Hermes
0.5.0+
HIGH 7.1
CVE-2025-0937
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other na…
Nomad
1.7.18 / 1.8.10+
CRITICAL 9.1
CVE-2025-0377
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
Go Slug
0.16.3+
MEDIUM 6.5
CVE-2024-12678
Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload iden…
Nomad
1.7.16 / 1.8.8+
MEDIUM 5.9
CVE-2024-12289
Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller…
Boundary
0.16.4 / 0.17.3+
HIGH 7.7
CVE-2024-10975
Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized C…
Nomad
1.7.15 / 1.8.7+
HIGH 7.5
CVE-2024-8185
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack t…
Vault
1.16.12 / 1.17.8+