Skip to content
NomadGHSA-3934-423w-4jq3

HashiCorp Nomad vulnerable to symlink attack

Medium6.0CVE-2026-6959 · Published May 12, 2026 · updated Jun 25, 2026

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
< 1.11.0-rc.1.0.20260512123500-2a09fd62c2381.11.0-rc.1.0.20260512123500-2a09fd62c238
Details and references

More Nomad advisories

All Nomad
Advisory
HashiCorp Nomad vulnerable to a path traversal
High8.8May 12
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
High8.1Jun 11, 2025
Nomad: secrets in logs
Medium6.5Mar 10, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
Medium6.5Dec 20, 2024
Hashicorp Nomad Incorrect Authorization vulnerability
Medium7.7Nov 7, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking
Medium5.8Aug 15, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.