HashiCorp Inc.
First CVE: Nov 10, 2022Active for: 4 years
100
CVEs Published
More CVEs Published than 70% of tracked CNAs
20.0
Avg CVEs / Year
More Avg CVEs / Year than 68% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 33% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by HashiCorp Inc. as a CNA, 86.0% affect products that HashiCorp Inc. develops as a vendor.
86.0%
14.0%
Self-reported: 86Third-party: 14
Of all the CVEs published that affect products developed by HashiCorp Inc., 44.3% are self-published by HashiCorp Inc. as a CNA.
44.3%
55.7%
Self-published: 86Published by other CNAs: 108
Trends Over Time
The number and severity of CVEs published by HashiCorp Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2022
3 years ago
Most Recent CVE
Jul 8, 2026
17 days ago
Top CVEs
All CVEs published by HashiCorp Inc. as a CNA, regardless of affected vendor or product.
100 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-14891HIGH HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even whe | Jul 8, 2026 | 8.7 | 37 | NO | NO |
CVE-2026-7474HIGH HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed | May 12, 2026 | 8.8 | 37 | NO | NO |
CVE-2025-13357CRITICAL Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If | Nov 21, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-6000CRITICAL A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’ | Aug 1, 2025 | 9.1 | 34 | NO | NO |
CVE-2026-7776HIGH Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with netw | May 4, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-4525HIGH If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to | Apr 17, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-0969HIGH The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-202 | Feb 12, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-14373HIGH HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job | Jul 8, 2026 | 7.7 | 30 | NO | NO |
CVE-2026-14468HIGH HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged | Jul 6, 2026 | 7.7 | 30 | NO | NO |
CVE-2026-4660HIGH HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CV | Apr 9, 2026 | 7.5 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA100 CVEs
44%
44%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (13.0%)
Network86 (86.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.0%)
Attack Complexity
Low88 (88.0%)
High12 (12.0%)
Unknown0 (0.0%)
User Interaction
None90 (90.0%)
Unknown0 (0.0%)
Required10 (10.0%)
Privileges Required
Low44 (44.0%)
High17 (17.0%)
None39 (39.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (100 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by HashiCorp Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by HashiCorp Inc. as a CNA — matched by CVE ID, not by organization name.