NomadGHSA-3934-423w-4jq3
HashiCorp Nomad vulnerable to symlink attack
Medium6.0CVE-2026-6959 · Published May 12, 2026 · updated Jun 25, 2026
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 1.11.0-rc.1.0.20260512123500-2a09fd62c238 | 1.11.0-rc.1.0.20260512123500-2a09fd62c238 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-59
- Also known as
- CVE-2026-6959, GO-2026-5076
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 12 | HashiCorp Nomad vulnerable to a path traversal | High8.8 | 1.11.0-rc.1.0.20260511152149-cd7240c4099a |
| Jun 112025 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | High8.1 | 1.10.2 |
| Mar 102025 | Nomad: secrets in logs | Medium6.5 | No fix yet |
| Dec 202024 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | Medium6.5 | 1.9.4 |
| Nov 72024 | Hashicorp Nomad Incorrect Authorization vulnerability | Medium7.7 | No fix yet |
| Aug 152024 | Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking | Medium5.8 | 1.6.14+2 more |