Skip to content
BoundaryGHSA-xx83-cxmq-x89m

Boundary Community Edition and Boundary Enterprise

Medium5.9CVE-2024-12289 · Published Dec 13, 2024 · updated Feb 3, 2026

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/boundary
Go
< 0.18.20.18.2
Details and references

More Boundary advisories

All Boundary
Advisory
Boundary: denial of service
High7.5May 5
Boundary vulnerable to session hijacking through TLS certificate tampering
High8.0Feb 5, 2024
HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service Configured
High7.1Jul 6, 2023
Hashicorp Boundary vulnerable to clickjacking
Medium6.1Oct 27, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.