Terraform provider
This hub aggregates every CVE we track for Terraform provider, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
1
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Terraform provider.
- CVE-2026-25499terraform-provider-proxmox has insecure sudo recommendation in the documentation7.5
- CVE-2025-13357Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method7.4
- CVE-2021-30476HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.9.8
Product normalization is registry-driven with AI assist and human review. How it works