PatchSiren

HashiCorp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM HashiCorp CVE published 2026-09-15

CVE-2026-88922

A vulnerability in the go-getter library up to versions 1.8.8 and 2.2.3 allows for privilege escalation through archive decompression handling. This may enable a local actor to gain elevated privileges if extraction is performed by a privileged user. The vulnerability is fixed in go-getter versions 1.8.9 and 2.2.4. Defenders should assess exposure and prioritize verification and remediation efforts. The C [truncated]

MEDIUM Hashicorp CVE published 2026-08-19

CVE-2026-14978

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T21:16:54.007Z and has not been modified since then. CVE-2026-14978 is a medium-severity vulnerability in Hashicorp Go-Slug, a tool used for creating Terraform slugs. The issue arises from improper handling of Unicode normalization during path matching, which could allow a local attacker to bypass [truncated]

HIGH HashiCorp CVE published 2026-08-10

CVE-2026-14886

The CVE-2026-14886 vulnerability affects Vault Enterprise's identity entity batch-delete endpoint, allowing cross-namespace authorization bypass. This high-severity issue (CVSS score of 8.2) may enable an authenticated caller in one namespace to permanently delete the storage backing of entities in another namespace. The vulnerability is addressed in Vault Enterprise versions 2.0.4, 1.21.9, 1.20.14, and 1 [truncated]

MEDIUM HashiCorp CVE published 2026-08-07

CVE-2026-19113

CVE-2026-19113 AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T20:16:50.787Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cau [truncated]

MEDIUM HashiCorp CVE published 2026-08-07

CVE-2026-19015

CVE-2026-19015 is an uncontrolled resource consumption issue in the Connect CA roots endpoint of Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2. This vulnerability may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. The issue is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

MEDIUM HashiCorp CVE published 2026-08-07

CVE-2026-19012

CVE-2026-19012 is an authenticated denial of service vulnerability affecting Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2. An authorized caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This issue is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

HIGH HashiCorp CVE published 2026-08-07

CVE-2026-15972

CVE-2026-15972 AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T20:16:50.020Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This unauthenticated denial of service vulnerability affects Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2, potentially allowing a remote attacker to exhaust agen [truncated]

HIGH HashiCorp CVE published 2026-07-06

CVE-2026-14468

CVE-2026-14468 is a vulnerability in HashiCorp Terraform Enterprise's version control system (VCS) ingestion of registry modules. The issue did not correctly enforce the intended boundary on packaged module content, potentially allowing an authenticated user to include and download files from outside the intended repository content. This could expose sensitive files readable by the ingestion process. The [truncated]

HIGH Hashicorp CVE published 2026-04-17

CVE-2026-4525

CVE-2026-4525 is a high-severity vulnerability in Hashicorp Vault that may expose tokens to auth plugins due to incorrect header sanitization. The vulnerability has a CVSS score of 7.5 and is considered HIGH. It was published on April 17, 2026, and modified on June 30, 2026. The vulnerability affects Hashicorp Vault versions prior to 2.0.0, 1.21.5, 1.20.10, and 1.19.16. Hashicorp has released fixed versio [truncated]

HIGH Hashicorp CVE published 2026-04-17

CVE-2026-3605

CVE-2026-3605 is a high-severity vulnerability in Hashicorp Vault, allowing authenticated users to delete secrets they are not authorized to access, resulting in a denial-of-service. This vulnerability, with a CVSS score of 8.1, was fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16. The vulnerability did not allow malicious users to delete secrets across names [truncated]

HIGH HashiCorp CVE published 2026-04-09

CVE-2026-4660

CVE-2026-4660 is a vulnerability in HashiCorp's go-getter library up to version 1.8.5 that may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. The vulnerability is fixed in go-getter version 1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. The CVSS score for this vulnerability is 7.5, indicating a high severity. T [truncated]