Skip to content
HashiCorpCVE-2026-14362

HashiCorp Shared library: denial of service

Medium4.9CVE-2026-14362 · Published Jul 8, 2026 · updated Jul 9, 2026

HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Shared library
Product
>= 0.1.5, < 0.6.00.6.0
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Nomad: improper authorization
Medium4.2Jul 8
HashiCorp Nomad: missing authorization
High7.7Jul 8
HashiCorp Nomad: link following
High8.7Jul 8
HashiCorp Tooling: link following
Medium4.7Jul 8
HashiCorp Terraform Enterprise: path traversal
High7.7Jul 6
HashiCorp Vault: path traversal
Medium4.4Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.