HashiCorp develops a focused but strategically critical portfolio of infrastructure-automation and secrets-management products—Vault, Nomad, and Consul among them—that sit at the foundation of cloud-native and multi-cloud deployments and are embedded across high-value enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the sensitive nature of access control, credential handling, and orchestration logic that these tools govern. The recurring weakness classes center on privilege and credential management issues—incorrect privilege assignment, improper certificate validation, and insertion of sensitive information into logs—alongside resource-exhaustion conditions, which align with the authentication, authorization, and state-management demands of infrastructure platforms. Defenders should treat HashiCorp disclosures as urgent and broadly applicable across their infrastructure estate, especially those touching Vault or identity workflows. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by HashiCorp Inc. over time
Of all the CVEs published by HashiCorp Inc. as a CNA, 86.0% affect products that HashiCorp Inc. develops as a vendor.
Of all the CVEs published that affect products developed by HashiCorp Inc., 44.3% are self-published by HashiCorp Inc. as a CNA.
Signals from CVEs in this vendor scope (194 CVEs).
194 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41805HIGH HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in | Dec 12, 2021 | 8.8 | 47 | NO | NO |
CVE-2022-29153HIGH HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health | Apr 19, 2022 | 7.5 | 39 | NO | YES |
CVE-2021-44139HIGH Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF). | Mar 23, 2022 | 7.5 | 37 | NO | YES |
CVE-2017-11741HIGH HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code wit | Aug 8, 2017 | 8.8 | 37 | NO | YES |
CVE-2025-13357CRITICAL Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If | Nov 21, 2025 | 9.8 | 35 | NO | NO |
CVE-2017-12579HIGH An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell. | Oct 19, 2017 | 7.8 | 35 | NO | YES |
CVE-2025-6000CRITICAL A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’ | Aug 1, 2025 | 9.1 | 34 | NO | NO |
CVE-2017-16001HIGH In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root | Nov 6, 2017 | 7.8 | 34 | NO | YES |
CVE-2017-7642HIGH The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify t | Aug 2, 2017 | 7.8 | 34 | NO | YES |
CVE-2017-16777HIGH If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and expl | Nov 16, 2017 | 7.8 | 33 | NO | YES |
Signals from CVEs in this vendor scope (194 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by HashiCorp Inc..
Media articles that mention a CVE ID that affects a product developed by HashiCorp Inc. — matched by CVE ID, not by vendor name.