Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: consul-alerts

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-2808
6.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 week, 3 days ago
Consul vulnerable to arbitrary file reads through the vault kubernetes authentication provider

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

Affected products

Consul
  • <1.22.5
Consul Enterprise
  • <1.22.5

Matching in nixpkgs

Package maintainers