Skip to content

HashiCorp vulnerabilities

2 CVEs tracked

Microsoft Threat Intelligence has uncovered a large-scale npm supply chain attack that targets secrets stores including HashiCorp Vault, putting cloud credential rotation at high priority. HashiCorp's reporting context this period features two key vulnerabilities: CVE-2026-55100, an encoding flaw in `hashi-vault-js` leading to path/query injection, and CVE-2026-19017, a partial arbitrary file read in Consul when using the Vault Connect CA provider. Defenders should audit CI/workflow environments interacting with Vault, scan for affected `hashi-vault-js` dependencies to prevent token-based propagation, apply patches for CVE-2026-55100, and restrict permissions on impacted Consul versions.

Azərbaycanca: Microsoft təhlükə kəşfiyyatı, HashiCorp-un bulud etimadnamələrinin oğurlanması potensialı səbəbilə HashiCorp Vault-ı da hədəf alan genişmiqyaslı npm təchizat zənciri hücumunu aşkarlayıb. Bu hesabat dövründə `hashi-vault-js` (CVE-2026-55100) üçün path/query enjeksiyonuna yol açan kodlaşdırma zəifliyi və Consul-da qismən ixtiyari fayl oxumağa imkan verən boşluq (CVE-2026-19017) daxil olmaqla kritik boşluqlar aşkarlanıb. Müdafiəçilər Vault kimi məxfi saxlanc həlləri ilə qarşılıqlı əlaqədə olan CI/İş axını mühitlərini nəzərdən keçirməli, oğurlanmış nişanlar vasitəsilə yayılan `hashi-vault-js` asılılıqları üçün skan etməli, CVE-2026-55100 üçün yamaları tətbiq etməli və təsirlənmiş Consul versiyalarında icazələri məhdudlaşdırmalıdır.

This vendor's CVEs2

This hub is built from skopnix's own reporting on HashiCorp: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.