Information Disclosure Vulnerability in Consul-Template by HashiCorp
CVE-2026-87993
7.7HIGH
What is CVE-2026-87993?
The consul-template library developed by HashiCorp is impacted by an information disclosure vulnerability in its error handling mechanism. This flaw may inadvertently expose sensitive Vault secret values in error messages, log entries, and external outputs such as Nomad task events. Users of affected versions should upgrade to consul-template 0.43.0 or later to mitigate this security risk.
Affected Version(s)
Tooling 64 bit 0.27.2 < 0.43.0
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was reported to HashiCorp by Ali Firas (thesmartshadow).