Skip to content
NomadGHSA-7v3g-4878-5qrf

Nomad Panics On Job Submission With Bad Artifact Stanza Source URL

Medium6.5CVE-2022-41606 · Published Oct 12, 2022 · updated May 20, 2025

HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
< 1.2.131.2.13
>= 1.3.0, < 1.3.61.3.6
Details and references

More Nomad advisories

All Nomad
Advisory
Nomad Job Submitter Privilege Escalation Using Workload Identity
High8.8Mar 14, 2023
Uncontrolled Resource Consumption in Hashicorp Nomad
Medium6.5Feb 17, 2023
HashiCorp Nomad vulnerable to Insufficient Session Expiration
Low2.7Nov 10, 2022
HashiCorp Nomad vulnerable to non-sensitive metadata exposure
Medium5.0Nov 10, 2022
Privilege escalation in Hashicorp Nomad
Critical9.8Jun 3, 2022
Hashicorp Nomad Access Control Issues
Critical9.8May 24, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.