Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

HashiCorp Inc.

First CVE: Aug 2, 2017Active for: 9 yearsTotal CVEs: 194
43.7
VTI Score
High

HashiCorp develops a focused but strategically critical portfolio of infrastructure-automation and secrets-management products—Vault, Nomad, and Consul among them—that sit at the foundation of cloud-native and multi-cloud deployments and are embedded across high-value enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the sensitive nature of access control, credential handling, and orchestration logic that these tools govern. The recurring weakness classes center on privilege and credential management issues—incorrect privilege assignment, improper certificate validation, and insertion of sensitive information into logs—alongside resource-exhaustion conditions, which align with the authentication, authorization, and state-management demands of infrastructure platforms. Defenders should treat HashiCorp disclosures as urgent and broadly applicable across their infrastructure estate, especially those touching Vault or identity workflows. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
194
Total CVEs
More Total CVEs than 100% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by HashiCorp Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2017
8 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

Self-Reporting Analysis

Of all the CVEs published by HashiCorp Inc. as a CNA, 86.0% affect products that HashiCorp Inc. develops as a vendor.

86.0%
14.0%
Self-reported: 86 (86.0%)
Third-party: 14 (14.0%)

Of all the CVEs published that affect products developed by HashiCorp Inc., 44.3% are self-published by HashiCorp Inc. as a CNA.

44.3%
55.7%
Self-published: 86 (44.3%)
Other CNAs: 108 (55.7%)

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (194 CVEs).

194 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41805HIGH
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in
Dec 12, 20218.847NONO
CVE-2022-29153HIGH
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health
Apr 19, 20227.539NOYES
CVE-2021-44139HIGH
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
Mar 23, 20227.537NOYES
CVE-2017-11741HIGH
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code wit
Aug 8, 20178.837NOYES
CVE-2025-13357CRITICAL
Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If
Nov 21, 20259.835NONO
CVE-2017-12579HIGH
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.
Oct 19, 20177.835NOYES
CVE-2025-6000CRITICAL
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’
Aug 1, 20259.134NONO
CVE-2017-16001HIGH
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root
Nov 6, 20177.834NOYES
CVE-2017-7642HIGH
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify t
Aug 2, 20177.834NOYES
CVE-2017-16777HIGH
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and expl
Nov 16, 20177.833NOYES
View all 194 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products194 CVEs
38%
48%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local21 (10.8%)
Network171 (88.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (1.0%)
Attack Complexity
Low175 (90.2%)
High19 (9.8%)
Unknown0 (0.0%)
User Interaction
None181 (93.3%)
Unknown0 (0.0%)
Required13 (6.7%)
Privileges Required
Low74 (38.1%)
High14 (7.2%)
None106 (54.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (194 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
1.5% of CVEs· 95th percentile
ExploitDB
6 CVEs
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by HashiCorp Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by HashiCorp Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For HashiCorp Inc.'s Products

View all 4 CNAs →

Top CWEs