CVE-2026-7776

7.5

HashiCorp · Boundary

HashiCorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes caused by unthrottled connection handling.

Executive summary

An unauthenticated denial-of-service vulnerability in HashiCorp Boundary workers allows remote attackers to disrupt node enrollment and routing through TLS handshake manipulation.

Vulnerability

This issue is an allocation of resources without limits or throttling, classified as CWE-770. An unauthenticated attacker with network access to the worker authentication listener can withhold client certificates during the TLS handshake to block connection handling.

Business impact

A successful exploit of this vulnerability results in a denial of service, preventing legitimate worker connections from being accepted or routed across the infrastructure. This disruption can halt administrative access workflows and impair remote session management capabilities. With a CVSS score of 7.5, the high severity rating reflects the ease of remote exploitation and the critical impact on service availability.

Remediation

Immediate Action: Update HashiCorp Boundary Community Edition and Boundary Enterprise to version 0.21.3, 0.20.3, 0.19.5, or later.

Proactive Monitoring: Monitor network infrastructure and application logs for unusual spikes in pending TLS handshakes or dropped worker connections.

Compensating Controls: Restrict network access to the worker authentication listener to trusted IP addresses using firewalls or security groups until updates can be applied.

Exploitation status

Public Exploit Available: No (no confirmed public exploit or weaponized module currently exists in the available data).

Analyst recommendation

Security teams must prioritize updating HashiCorp Boundary deployments to the latest patched releases to mitigate availability risks. Applying these updates immediately ensures worker resilience against resource exhaustion during the TLS handshake phase.

More HashiCorp CVEs

Sources

Originally found and disclosed by This issue was identified by the Boundary Engineering team., per the CVE Program record.