NomadGHSA-hx53-77qj-8663
HashiCorp Nomad vulnerable to a path traversal
High8.8CVE-2026-7474 · Published May 12, 2026 · updated Jun 25, 2026
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 1.11.0-rc.1.0.20260511152149-cd7240c4099a | 1.11.0-rc.1.0.20260511152149-cd7240c4099a |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2026-7474, GO-2026-5445
- nvd.nist.gov/vuln/detail/CVE-2026-7474
- github.com/hashicorp/nomad/commit/cd7240c4099ad33eda279924fb3a9459b162d120
- discuss.hashicorp.com/t/hcsec-2026-15-nomad-vulnerable-to-path-traversal-in-dynamic-host-volume-which-may-lead-to-code-execution/77417
- github.com/hashicorp/nomad
- github.com/hashicorp/nomad/releases/tag/v2.0.1
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 12 | HashiCorp Nomad vulnerable to symlink attack | Medium6.0 | 1.11.0-rc.1.0.20260512123500-2a09fd62c238 |
| Jun 112025 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | High8.1 | 1.10.2 |
| Mar 102025 | Nomad: secrets in logs | Medium6.5 | No fix yet |
| Dec 202024 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | Medium6.5 | 1.9.4 |
| Nov 72024 | Hashicorp Nomad Incorrect Authorization vulnerability | Medium7.7 | No fix yet |
| Aug 152024 | Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking | Medium5.8 | 1.6.14+2 more |