HashiCorp Inc.

First CVE: Nov 10, 2022Active for: 4 years
100
CVEs Published
More CVEs Published than 70% of tracked CNAs
20.0
Avg CVEs / Year
More Avg CVEs / Year than 68% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 33% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by HashiCorp Inc. as a CNA, 86.0% affect products that HashiCorp Inc. develops as a vendor.

86.0%
14.0%
Self-reported: 86Third-party: 14

Of all the CVEs published that affect products developed by HashiCorp Inc., 44.3% are self-published by HashiCorp Inc. as a CNA.

44.3%
55.7%
Self-published: 86Published by other CNAs: 108

Trends Over Time

The number and severity of CVEs published by HashiCorp Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2022
3 years ago
Most Recent CVE
Jul 8, 2026
17 days ago

Top CVEs

All CVEs published by HashiCorp Inc. as a CNA, regardless of affected vendor or product.

100 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even whe
Jul 8, 20268.737NONO
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed
May 12, 20268.837NONO
Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If
Nov 21, 20259.835NONO
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’
Aug 1, 20259.134NONO
Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with netw
May 4, 20267.531NONO
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to
Apr 17, 20268.831NONO
The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-202
Feb 12, 20268.831NONO
HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job
Jul 8, 20267.730NONO
HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged
Jul 6, 20267.730NONO
HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CV
Apr 9, 20267.530NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA100 CVEs
Severity distribution among all CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local13 (13.0%)
Network86 (86.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.0%)
Attack Complexity
Low88 (88.0%)
High12 (12.0%)
Unknown0 (0.0%)
User Interaction
None90 (90.0%)
Unknown0 (0.0%)
Required10 (10.0%)
Privileges Required
Low44 (44.0%)
High17 (17.0%)
None39 (39.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (100 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by HashiCorp Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by HashiCorp Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs