Github.com/hashicorp/nomad
This hub aggregates every CVE we track for Github.com/hashicorp/nomad, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
32
CVEs tracked
5
Critical
11
High
0
In CISA KEV
Severity distribution
MEDIUM13HIGH11CRITICAL5LOW3
Monthly trend
1
1
0
0
1
1
0
0
1
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Github.com/hashicorp/nomad.
- CVE-2025-4922Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job8.1
- CVE-2025-1296Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs6.5
- CVE-2024-12678Nomad Allocations Vulnerable To Privilege Escalation Within A Namespace Using Unredacted Workload Identity Tokens6.5
- CVE-2024-10975Nomad Vulnerable To Cross-Namespace Volume Creation Abusing CSI Write Permission7.7
- CVE-2024-7625Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking5.8
- CVE-2024-6717Nomad Vulnerable to Allocation Directory Path Escape Through Archive Unpacking7.7
- CVE-2024-1329Nomad Vulnerable to Arbitrary Write Through Symlink Attack7.7
- CVE-2023-3300Nomad Search API Leaks Information About CSI Plugins5.3
- CVE-2023-3299Nomad Caller ACL Token's Secret ID is Exposed to Sentinel3.4
- CVE-2023-3072Nomad ACL Policies without Label are Applied to Unexpected Resources4.1
- CVE-2023-1782Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation9.9
- CVE-2023-1299Nomad Job Submitter Privilege Escalation Using Workload Identity7.4
- CVE-2023-1296Nomad ACLs Can Not Deny Access to Workload's Own Variables2.7
- CVE-2023-0821Nomad Client Vulnerable to Decompression Bombs in Artifact Block6.5
- CVE-2019-14802HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/...5.3
Product normalization is registry-driven with AI assist and human review. How it works