Skip to content
boundaryGHSA-7x9r-wcgg-w86f

Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes

High7.5CVE-2026-7776 · Published May 5, 2026 · updated Jul 21, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/boundary
Go
< 0.19.50.19.5
>= 0.20.0, < 0.20.30.20.3
>= 0.21.0, < 0.21.30.21.3
Details and references

Boundary Community Edition and Boundary Enterprise ("Boundary") workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate worker connections from being accepted or routed. This vulnerability, CVE-2026-7776, is fixed in Boundary 0.21.3, 0.20.3, 0.19.5.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-770
Also known as
CVE-2026-7776, GO-2026-5237

More boundary advisories

All
DateAdvisory
Dec 132024Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service
CVE-2024-12289Medium5.9fixed in 0.18.2
Feb 52024Boundary vulnerable to session hijacking through TLS certificate tampering
CVE-2024-1052High8.0fixed in 0.15.0
Jul 62023HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured
CVE-2023-0690High7.1fixed in 0.12.0
Oct 272022Hashicorp Boundary vulnerable to clickjacking
CVE-2022-36182Medium6.1no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.