github.com/hashicorp/nomad
Nomad is an easy-to-use, flexible, and performant workload orchestrator that can deploy a mix of microservice, batch, containerized, and non-containerized applications. Nomad is easy to operate and scale and has native Consul and Vault integrations.
Activity
- Latest release
- 6mo ago
- Total releases
- 64
- Cadence
- ~27 days
- Last 12 months
- 6
Reach
- Stars
- 16.8k
Details
- First release
- Nov 19, 2015
| Version | Released | |
|---|---|---|
v1.11.3
patch
|
v1.11.3
patch
Dependencies (126)
+ 118 more |
|
v1.11.2
patch
|
v1.11.2
patch
Dependencies (126)
+ 118 more |
|
v1.11.1
minor
|
v1.11.1
minor
Dependencies (126)
+ 118 more |
|
v1.11.0
minor
1 CVE
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.0
minor
Dependencies (124)
+ 116 more |
|
v1.11.0-rc.1
pre
3 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.0-rc.1
pre
Dependencies (124)
+ 116 more |
|
v1.11.0-beta.1
pre
3 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.0-beta.1
pre
Dependencies (124)
+ 116 more |
|
v1.10.5
patch
3 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.5
patch
Dependencies (124)
+ 116 more |
|
v1.10.4
patch
3 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.4
patch
Dependencies (124)
+ 116 more |
|
v1.10.3
minor
3 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.3
minor
Dependencies (124)
+ 116 more |
|
v1.10.2
patch
3 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.2
patch
Dependencies (124)
+ 116 more |
|
v1.10.1
patch
4 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.1
patch
Dependencies (123)
+ 115 more |
|
v1.10.0
minor
4 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.0
minor
Dependencies (124)
+ 116 more |
|
v1.10.0-rc.1
pre
4 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.0-rc.1
pre
Dependencies (124)
+ 116 more |
|
v1.10.0-beta.1
pre
4 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.10.0-beta.1
pre
Dependencies (124)
+ 116 more |
|
v1.9.7
patch
4 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.7
patch
Dependencies (127)
+ 119 more |
|
v1.9.6
patch
5 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.6
patch
Dependencies (127)
+ 119 more |
|
v1.9.5
minor
5 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.5
minor
Dependencies (129)
+ 121 more |
|
v1.9.4
patch
5 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.4
patch
Dependencies (125)
+ 117 more |
|
v1.9.3
minor
6 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.9.3
minor
Dependencies (125)
+ 117 more |
|
v1.8.4
patch
7 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.8.4
patch
Dependencies (123)
+ 115 more |
|
v1.8.1
minor
8 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev |
v1.8.1
minor
Dependencies (119)
+ 111 more |
|
v1.7.6
patch
8 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.6
patch
Dependencies (121)
+ 113 more |
|
v1.5.14
minor
8 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev |
v1.5.14
minor
Dependencies (118)
+ 110 more |
|
v1.6.7
patch
8 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev |
v1.6.7
patch
Dependencies (118)
+ 110 more |
|
v1.7.4
minor
8 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev |
v1.7.4
minor
Dependencies (121)
+ 113 more |
|
v1.6.6
patch
9 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2024-1329
GO-2024-2538
GHSA-c866-8gpw-p3mv
Mar 04, 2024
Symlink attack in github.com/hashicorp/nomad Symlink attack in github.com/hashicorp/nomad Fixed in
1.5.14
1.6.7
1.7.4
References
Updated May 20, 2024 · Source: OSV.dev |
v1.6.6
patch
Dependencies (118)
+ 110 more |
|
v1.6.2
minor
9 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2024-1329
GO-2024-2538
GHSA-c866-8gpw-p3mv
Mar 04, 2024
Symlink attack in github.com/hashicorp/nomad Symlink attack in github.com/hashicorp/nomad Fixed in
1.5.14
1.6.7
1.7.4
References
Updated May 20, 2024 · Source: OSV.dev |
v1.6.2
minor
Dependencies (120)
+ 112 more |
|
v1.3.16
patch
11 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3299
GO-2024-2669
GHSA-9jfx-84v9-2rr2
Apr 04, 2024
API token secret ID leak to Sentinel in github.com/hashicorp/nomad A vulnerability exists in Nomad where the API caller's ACL token secret ID is exposed to Sentinel policies. Fixed in
1.4.11
1.5.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.16
patch
Dependencies (111)
+ 103 more |
|
v1.3.14
patch
11 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3299
GO-2024-2669
GHSA-9jfx-84v9-2rr2
Apr 04, 2024
API token secret ID leak to Sentinel in github.com/hashicorp/nomad A vulnerability exists in Nomad where the API caller's ACL token secret ID is exposed to Sentinel policies. Fixed in
1.4.11
1.5.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.14
patch
Dependencies (111)
+ 103 more |
|
v1.4.8
patch
11 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3299
GO-2024-2669
GHSA-9jfx-84v9-2rr2
Apr 04, 2024
API token secret ID leak to Sentinel in github.com/hashicorp/nomad A vulnerability exists in Nomad where the API caller's ACL token secret ID is exposed to Sentinel policies. Fixed in
1.4.11
1.5.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.8
patch
Dependencies (114)
+ 106 more |
|
v1.3.12
patch
11 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3299
GO-2024-2669
GHSA-9jfx-84v9-2rr2
Apr 04, 2024
API token secret ID leak to Sentinel in github.com/hashicorp/nomad A vulnerability exists in Nomad where the API caller's ACL token secret ID is exposed to Sentinel policies. Fixed in
1.4.11
1.5.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.12
patch
Dependencies (111)
+ 103 more |
|
v1.4.7
minor
11 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3299
GO-2024-2669
GHSA-9jfx-84v9-2rr2
Apr 04, 2024
API token secret ID leak to Sentinel in github.com/hashicorp/nomad A vulnerability exists in Nomad where the API caller's ACL token secret ID is exposed to Sentinel policies. Fixed in
1.4.11
1.5.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.7
minor
Dependencies (114)
+ 106 more |
|
v1.5.0-rc.1
pre
8 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev |
v1.5.0-rc.1
pre
Dependencies (118)
+ 110 more |
|
v1.3.8
patch
12 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0821
GO-2023-1581
GHSA-w479-w22g-cffh
Aug 20, 2024
Uncontrolled Resource Consumption in Hashicorp Nomad in github.com/hashicorp/nomad Uncontrolled Resource Consumption in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.2.16
1.3.9
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3299
GO-2024-2669
GHSA-9jfx-84v9-2rr2
Apr 04, 2024
API token secret ID leak to Sentinel in github.com/hashicorp/nomad A vulnerability exists in Nomad where the API caller's ACL token secret ID is exposed to Sentinel policies. Fixed in
1.4.11
1.5.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.8
patch
Dependencies (111)
+ 103 more |
|
v1.3.7
minor
12 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-0821
GO-2023-1581
GHSA-w479-w22g-cffh
Aug 20, 2024
Uncontrolled Resource Consumption in Hashicorp Nomad in github.com/hashicorp/nomad Uncontrolled Resource Consumption in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.2.16
1.3.9
1.4.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3299
GO-2024-2669
GHSA-9jfx-84v9-2rr2
Apr 04, 2024
API token secret ID leak to Sentinel in github.com/hashicorp/nomad A vulnerability exists in Nomad where the API caller's ACL token secret ID is exposed to Sentinel policies. Fixed in
1.4.11
1.5.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.7
minor
Dependencies (111)
+ 103 more |
|
v1.1.18
patch
11 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.1.18
patch
Dependencies (105)
+ 97 more |
|
v1.2.11
minor
12 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3299
GO-2024-2669
GHSA-9jfx-84v9-2rr2
Apr 04, 2024
API token secret ID leak to Sentinel in github.com/hashicorp/nomad A vulnerability exists in Nomad where the API caller's ACL token secret ID is exposed to Sentinel policies. Fixed in
1.4.11
1.5.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.11
minor
Dependencies (106)
+ 98 more |
|
v1.1.15
patch
11 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.1.15
patch
Dependencies (105)
+ 97 more |
|
v1.1.14
patch
11 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.1.14
patch
Dependencies (105)
+ 97 more |
|
v1.1.13
patch
12 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.1.13
patch
Dependencies (105)
+ 97 more |
|
v1.0.17
patch
15 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.17
patch
Dependencies (99)
+ 91 more |
|
v1.0.14
patch
16 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24685
GO-2022-0577
GHSA-3382-r9q8-4hfg
Aug 21, 2024
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad Fixed in
1.0.17
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.14
patch
Dependencies (99)
+ 91 more |
|
v1.1.7
patch
17 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43415
GO-2022-0573
GHSA-2jhh-5xm2-j4gf
Aug 21, 2024
Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.14
1.1.8
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24685
GO-2022-0577
GHSA-3382-r9q8-4hfg
Aug 21, 2024
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad Fixed in
1.0.17
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.1.7
patch
Dependencies (103)
+ 95 more |
|
v1.0.7
patch
18 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37218
GO-2022-0591
GHSA-c8x3-rg72-fwwg
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.10
1.1.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43415
GO-2022-0573
GHSA-2jhh-5xm2-j4gf
Aug 21, 2024
Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.14
1.1.8
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24685
GO-2022-0577
GHSA-3382-r9q8-4hfg
Aug 21, 2024
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad Fixed in
1.0.17
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.7
patch
Dependencies (99)
+ 91 more |
|
v1.1.0
minor
18 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37218
GO-2022-0591
GHSA-c8x3-rg72-fwwg
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.10
1.1.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43415
GO-2022-0573
GHSA-2jhh-5xm2-j4gf
Aug 21, 2024
Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.14
1.1.8
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24685
GO-2022-0577
GHSA-3382-r9q8-4hfg
Aug 21, 2024
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad Fixed in
1.0.17
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.1.0
minor
Dependencies (100)
+ 92 more |
|
v1.0.1
major
20 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32575
GO-2022-0709
GHSA-vf6q-9f2f-mwhv
Aug 21, 2024
Improper network isolation in Hashicorp Nomad in github.com/hashicorp/nomad Improper network isolation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
0.12.12
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3283
GO-2022-0622
GHSA-35qp-xq9f-2rjx
Aug 21, 2024
Improper Privilege Management in HashiCorp Nomad in github.com/hashicorp/nomad Improper Privilege Management in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
0.12.10
1.0.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37218
GO-2022-0591
GHSA-c8x3-rg72-fwwg
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.10
1.1.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43415
GO-2022-0573
GHSA-2jhh-5xm2-j4gf
Aug 21, 2024
Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.14
1.1.8
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24685
GO-2022-0577
GHSA-3382-r9q8-4hfg
Aug 21, 2024
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad Fixed in
1.0.17
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.1
major
Dependencies (99)
+ 91 more |
|
v0.11.8
patch
19 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32575
GO-2022-0709
GHSA-vf6q-9f2f-mwhv
Aug 21, 2024
Improper network isolation in Hashicorp Nomad in github.com/hashicorp/nomad Improper network isolation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
0.12.12
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3283
GO-2022-0622
GHSA-35qp-xq9f-2rjx
Aug 21, 2024
Improper Privilege Management in HashiCorp Nomad in github.com/hashicorp/nomad Improper Privilege Management in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
0.12.10
1.0.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37218
GO-2022-0591
GHSA-c8x3-rg72-fwwg
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.10
1.1.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43415
GO-2022-0573
GHSA-2jhh-5xm2-j4gf
Aug 21, 2024
Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.14
1.1.8
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v0.11.8
patch
|
|
v0.12.9
patch
19 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32575
GO-2022-0709
GHSA-vf6q-9f2f-mwhv
Aug 21, 2024
Improper network isolation in Hashicorp Nomad in github.com/hashicorp/nomad Improper network isolation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
0.12.12
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3283
GO-2022-0622
GHSA-35qp-xq9f-2rjx
Aug 21, 2024
Improper Privilege Management in HashiCorp Nomad in github.com/hashicorp/nomad Improper Privilege Management in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
0.12.10
1.0.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37218
GO-2022-0591
GHSA-c8x3-rg72-fwwg
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.10
1.1.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43415
GO-2022-0573
GHSA-2jhh-5xm2-j4gf
Aug 21, 2024
Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.14
1.1.8
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v0.12.9
patch
Dependencies (98)
+ 90 more |
|
v0.11.7
minor
19 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32575
GO-2022-0709
GHSA-vf6q-9f2f-mwhv
Aug 21, 2024
Improper network isolation in Hashicorp Nomad in github.com/hashicorp/nomad Improper network isolation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
0.12.12
1.0.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-3283
GO-2022-0622
GHSA-35qp-xq9f-2rjx
Aug 21, 2024
Improper Privilege Management in HashiCorp Nomad in github.com/hashicorp/nomad Improper Privilege Management in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
0.12.10
1.0.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37218
GO-2022-0591
GHSA-c8x3-rg72-fwwg
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.10
1.1.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43415
GO-2022-0573
GHSA-2jhh-5xm2-j4gf
Aug 21, 2024
Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.14
1.1.8
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v0.11.7
minor
|
|
v1.0.0-beta2
pre
17 CVEs
CVE-2026-7474
GO-2026-5445
GHSA-hx53-77qj-8663
Jun 25, 2026
HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to a path traversal in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260511152149-cd7240c4099a
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-6959
GO-2026-5076
GHSA-3934-423w-4jq3
Jun 25, 2026
HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad HashiCorp Nomad vulnerable to symlink attack in github.com/hashicorp/nomad Fixed in
1.11.0-rc.1.0.20260512123500-2a09fd62c238
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-6717
GO-2026-4278
GHSA-5mqx-rpxv-mvxj
Jan 12, 2026
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration in github.com/hashicorp/nomad Fixed in
1.11.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-4922
GO-2025-3758
GHSA-rx97-6c62-55mf
Jul 28, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.10.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-1296
GO-2025-3510
GHSA-c3q9-q986-vrwh
Mar 13, 2025
Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Unintentional exposure of the workload identity token and client secret in logs in github.com/hashicorp/nomad Fixed in
1.9.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-12678
GO-2024-3354
GHSA-hr68-hvgv-xxqf
Dec 20, 2024
Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad Fixed in
1.9.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-10975
GO-2024-3262
GHSA-2w5v-x29g-jw7j
Nov 08, 2024
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad Fixed in
1.9.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-41606
GO-2022-1062
GHSA-7v3g-4878-5qrf
Aug 21, 2024
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Nomad Panics On Job Submission With Bad Artifact Stanza Source URL in github.com/hashicorp/nomad Fixed in
1.2.13
1.3.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-30324
GO-2022-0732
GHSA-526x-rm7j-v389
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.1.14
1.2.8
1.3.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24683
GO-2022-0584
GHSA-wmrx-57hm-mw7r
Aug 21, 2024
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-37218
GO-2022-0591
GHSA-c8x3-rg72-fwwg
Aug 21, 2024
Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Privilege escalation in Hashicorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.10
1.1.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24686
GO-2022-0600
GHSA-gwmc-6795-qghj
Aug 21, 2024
HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad HashiCorp Nomad Artifact Download Race Condition in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43415
GO-2022-0573
GHSA-2jhh-5xm2-j4gf
Aug 21, 2024
Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Improper Authentication in HashiCorp Nomad in github.com/hashicorp/nomad Fixed in
1.0.14
1.1.8
1.2.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24684
GO-2022-0560
GHSA-6jm6-cmcp-fqjq
Aug 21, 2024
Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Nomad Spread Job Stanza May Trigger Panic in Servers in github.com/hashicorp/nomad Fixed in
1.0.18
1.1.12
1.2.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-7625
GO-2024-3073
GHSA-25qx-vfw2-fw8r
Aug 19, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking in github.com/hashicorp/nomad. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/nomad from v0.6.1 before v1.6.14, from v1.7.0 before v1.7.11, from v1.8.0 before v1.8.3. Fixed in
1.8.3
References Updated Aug 19, 2024 · Source: OSV.dev
CVE-2023-3072
GO-2024-2670
GHSA-rpvr-38xv-xvxq
Apr 04, 2024
ACL security vulnerability in github.com/hashicorp/nomad An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications. Fixed in
1.4.11
1.5.6
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-3300
GO-2024-2671
GHSA-v5fm-hr72-27hx
Apr 04, 2024
CSI plugin names disclosure in github.com/hashicorp/nomad A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability affects Nomad since 0.11.0 and was fixed in 1.4.11 and 1.5.7. Fixed in
1.4.11
1.5.7
References Updated May 20, 2024 · Source: OSV.dev |
v1.0.0-beta2
pre
Dependencies (99)
+ 91 more |