boundaryGHSA-7x9r-wcgg-w86f
Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
High7.5CVE-2026-7776 · Published May 5, 2026 · updated Jul 21, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/boundary Go | < 0.19.5 | 0.19.5 |
| >= 0.20.0, < 0.20.3 | 0.20.3 | |
| >= 0.21.0, < 0.21.3 | 0.21.3 |
Details and references
Boundary Community Edition and Boundary Enterprise ("Boundary") workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate worker connections from being accepted or routed. This vulnerability, CVE-2026-7776, is fixed in Boundary 0.21.3, 0.20.3, 0.19.5.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-770
- Also known as
- CVE-2026-7776, GO-2026-5237
More boundary advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 132024 | Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service CVE-2024-12289Medium5.9fixed in 0.18.2 | Medium5.9 | 0.18.2 |
| Feb 52024 | Boundary vulnerable to session hijacking through TLS certificate tampering CVE-2024-1052High8.0fixed in 0.15.0 | High8.0 | 0.15.0 |
| Jul 62023 | HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured CVE-2023-0690High7.1fixed in 0.12.0 | High7.1 | 0.12.0 |
| Oct 272022 | Hashicorp Boundary vulnerable to clickjacking CVE-2022-36182Medium6.1no fix yet | Medium6.1 | No fix yet |