hashicorp
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting hashicorp.
- CVE-2026-19113Unauthenticated denial of service via unbounded request body processing5.3
- CVE-2026-15972Unauthenticated denial of service via unbounded external gRPC connection acceptance7.5
- CVE-2026-15970L7 intention authorization bypass via custom public listener4.2
- CVE-2026-19017Consul vulnerable to partial arbitrary file read via Vault Connect CA provider6.8
- CVE-2026-19015Uncontrolled resource consumption in the Consul Connect CA roots endpoint5.3
- CVE-2026-19014Uncontrolled resource consumption in the Consul Connect authorization endpoint4.3
- CVE-2026-19012Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path5.3
- CVE-2026-19016Authorization bypass for session deletion in the transaction API4.2
- CVE-2026-16326consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode10.0
- CVE-2026-16328consul-mcp-server vulnerable to server side request forgery leading to token exposure8.6
- CVE-2026-16498terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode10.0
- CVE-2026-16496terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user8.9
- CVE-2026-14869terraform-mcp-server vulnerable to server side request forgery leading to token exposure8.6
- CVE-2026-14896Nomad vulnerable to cross-namespace host volume claim deletion4.2
- CVE-2026-14361Consul-template is vulnerable to path redirection in writeToFile through symlink attack4.7