23 Total CVEs
22 AI Analyzed
0 CISA KEV
3 Critical

Profile

0% ended up actively exploited 0 of 23 added to CISA KEV
13% rated critical (CVSS 9.0+) 3 critical, 20 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

19 CVEs in the last 12 months

Products

  • Terraform MCP Server3
  • Nomad and1
  • operation slot1
  • consul-mcp-server1
  • Consul-mcp-server1
  • Consul1
  • Nomad1
  • Vault Enterprise1

9 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-23 of 23 CVEs
CVE-2026-7776
Analyzed
7.5
HashiCorp Multiple Products

Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS han...

2026-05-05
CVE-2026-7474
Analyzed
8.8
HashiCorp Nomad and

HashiCorp Nomad and Nomad Enterprise prior to 2

2026-05-13
CVE-2026-5807
Analyzed
7.5
HashiCorp operation slot

Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or reke...

2026-04-17
CVE-2026-4660
Analyzed
7.5
HashiCorp Multiple Products

HashiCorp’s go-getter library up to v1

2026-04-10
CVE-2026-4525
Analyzed
7.5
HashiCorp Multiple Products

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault...

2026-04-17
CVE-2026-3605
Analyzed
8.1
HashiCorp Multiple Products

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or...

2026-04-17
CVE-2026-16498
Analyzed
10
HashiCorp Terraform MCP Server

A cross-tenant credential reuse vulnerability in HashiCorp terraform-mcp-server before 1.1.0 allows unauthorized access to tool calls by using a previ...

2026-07-29
CVE-2026-16496
Analyzed
8.9
HashiCorp Terraform MCP Server

The terraform-mcp-server before version 1

2026-07-29
CVE-2026-16328
Analyzed
8.6
HashiCorp consul-mcp-server

In consul-mcp-server, versions 0

2026-07-30
CVE-2026-16326
Analyzed
10
HashiCorp Consul-mcp-server

The HashiCorp consul-mcp-server fails to isolate session state in stateless mode, allowing one client's authentication token to be erroneously reused...

2026-07-30
CVE-2026-15972
Analyzed
7.5
HashiCorp Consul

Consul Community Edition and Consul Enterprise 1

2026-08-09
CVE-2026-14891
Analyzed
8.7
HashiCorp Nomad

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host...

2026-07-09
CVE-2026-14886
Analyzed
8.2
HashiCorp Vault Enterprise

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated calle...

2026-08-11
CVE-2026-14869
Analyzed
8.6
HashiCorp Terraform MCP Server

The terraform-mcp-server before version 1

2026-07-29
CVE-2026-14468
Analyzed
7.7
HashiCorp Terraform Enterprise

HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the...

2026-07-07
CVE-2026-0969
Analyzed
8.8
HashiCorp Multiple Products

The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX conten...

2026-02-12
CVE-2025-8959
7.5
HashiCorp Multiple Products

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated...

2025-08-15
CVE-2025-6203
Analyzed
7.5
HashiCorp Multiple Products

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory...

2025-08-28
CVE-2025-6000
Analyzed
9.1
HashiCorp Multiple Products

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plu...

2025-08-01
CVE-2025-5999
Analyzed
7.2
HashiCorp Multiple Products

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileg...

2025-08-01
CVE-2025-13357
Analyzed
7.4
HashiCorp Multiple Products

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in...

2025-11-22
CVE-2025-12044
Analyzed
7.5
HashiCorp Multiple Products

Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads

2025-10-23
CVE-2025-11621
Analyzed
8.1
HashiCorp Multiple Products

Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam i...

2025-10-23