Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: openbaoPlugins.secrets-nomad

Found 16 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-45808
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 2 weeks ago Activity log
  • Created suggestion
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. This is fixed in OpenBao v2.5.4.

Affected products

openbao
  • ==< 2.5.4

Matching in nixpkgs

pkgs.openbao

Open source, community-driven fork of Vault managed by the Linux Foundation

  • nixos-unstable -
    • nixos-unstable-small 2.7.0
  • nixos-26.05 -
    • nixos-26.05-small 2.6.2

pkgs.openbaoPlugins.auth-gcp

OpenBao auth plugin to authenticate using Google Cloud Platform credentials

  • nixos-unstable -

pkgs.openbaoPlugins.secrets-aws

OpenBao secrets plugin to generate AWS access credentials based on IAM policies

  • nixos-unstable -
    • nixos-unstable-small 0.3.1

pkgs.openbaoPlugins.secrets-gcp

OpenBao secrets plugin to generate GCP service account keys and OAuth tokens based on IAM policies

  • nixos-unstable -

pkgs.openbaoPlugins.secrets-azure

OpenBao secrets plugin to generate Azure service principals with role and group assignments

  • nixos-unstable -

Package maintainers

Untriaged
Permalink CVE-2026-14891
8.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 2 months, 2 weeks ago Activity log
  • Created suggestion
Nomad vulnerable to sandbox escape in Docker task driver

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

Affected products

Nomad
  • <2.0.4
Nomad Enterprise
  • <2.0.4

Matching in nixpkgs

pkgs.nomad

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomadnet

Off-grid, resilient mesh communication

  • nixos-unstable -
    • nixos-unstable-small 1.4.3

pkgs.git-nomad

Synchronize work-in-progress git branches in a light weight fashion

  • nixos-unstable -
    • nixos-unstable-small 0.9.0
  • nixos-26.05 -
    • nixos-26.05-small 0.9.0

pkgs.nomad_1_9

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
    • nixos-unstable-small 1.9.7
  • nixos-26.05 -
    • nixos-26.05-small 1.9.7

pkgs.nomad_2_0

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
    • nixos-unstable-small 2.0.0

pkgs.nomad-pack

Nomad Pack is a templating and packaging tool used with HashiCorp Nomad

  • nixos-unstable -
    • nixos-unstable-small 0.4.2
  • nixos-26.05 -
    • nixos-26.05-small 0.4.2

pkgs.nomad_1_10

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomad_1_11

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomad-autoscaler

Autoscaling daemon for Nomad

  • nixos-unstable -
    • nixos-unstable-small 0.3.6
  • nixos-26.05 -
    • nixos-26.05-small 0.3.6

Package maintainers

Untriaged
Permalink CVE-2026-14373
7.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 2 months, 2 weeks ago Activity log
  • Created suggestion
Nomad Docker driver Linux host namespace bypass

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

Affected products

Nomad
  • <2.0.4
Nomad Enterprise
  • <2.0.4

Matching in nixpkgs

pkgs.nomad

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomadnet

Off-grid, resilient mesh communication

  • nixos-unstable -
    • nixos-unstable-small 1.4.3

pkgs.git-nomad

Synchronize work-in-progress git branches in a light weight fashion

  • nixos-unstable -
    • nixos-unstable-small 0.9.0
  • nixos-26.05 -
    • nixos-26.05-small 0.9.0

pkgs.nomad_1_9

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
    • nixos-unstable-small 1.9.7
  • nixos-26.05 -
    • nixos-26.05-small 1.9.7

pkgs.nomad_2_0

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
    • nixos-unstable-small 2.0.0

pkgs.nomad-pack

Nomad Pack is a templating and packaging tool used with HashiCorp Nomad

  • nixos-unstable -
    • nixos-unstable-small 0.4.2
  • nixos-26.05 -
    • nixos-26.05-small 0.4.2

pkgs.nomad_1_10

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomad_1_11

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomad-autoscaler

Autoscaling daemon for Nomad

  • nixos-unstable -
    • nixos-unstable-small 0.3.6
  • nixos-26.05 -
    • nixos-26.05-small 0.3.6

Package maintainers

Untriaged
Permalink CVE-2026-14896
4.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 2 months, 2 weeks ago Activity log
  • Created suggestion
Nomad vulnerable to cross-namespace host volume claim deletion

HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

Affected products

Nomad
  • <2.0.4
Nomad Enterprise
  • <2.0.4

Matching in nixpkgs

pkgs.nomad

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomadnet

Off-grid, resilient mesh communication

  • nixos-unstable -
    • nixos-unstable-small 1.4.3

pkgs.git-nomad

Synchronize work-in-progress git branches in a light weight fashion

  • nixos-unstable -
    • nixos-unstable-small 0.9.0
  • nixos-26.05 -
    • nixos-26.05-small 0.9.0

pkgs.nomad_1_9

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
    • nixos-unstable-small 1.9.7
  • nixos-26.05 -
    • nixos-26.05-small 1.9.7

pkgs.nomad_2_0

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
    • nixos-unstable-small 2.0.0

pkgs.nomad-pack

Nomad Pack is a templating and packaging tool used with HashiCorp Nomad

  • nixos-unstable -
    • nixos-unstable-small 0.4.2
  • nixos-26.05 -
    • nixos-26.05-small 0.4.2

pkgs.nomad_1_10

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomad_1_11

Distributed, Highly Available, Datacenter-Aware Scheduler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nomad-autoscaler

Autoscaling daemon for Nomad

  • nixos-unstable -
    • nixos-unstable-small 0.3.6
  • nixos-26.05 -
    • nixos-26.05-small 0.3.6

Package maintainers

Untriaged
Permalink CVE-2026-42186
2.3 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 4 months, 1 week ago Activity log
  • Created suggestion
OpenBao's Namespace Deletion May Not Delete Data Properly

OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around. This vulnerability is fixed in 2.5.3.

Affected products

openbao
  • ==< 2.5.3

Matching in nixpkgs

pkgs.openbao

Open source, community-driven fork of Vault managed by the Linux Foundation

  • nixos-unstable -
    • nixos-unstable-small 2.7.0
  • nixos-26.05 -
    • nixos-26.05-small 2.6.2

pkgs.openbaoPlugins.auth-gcp

OpenBao auth plugin to authenticate using Google Cloud Platform credentials

  • nixos-unstable -

pkgs.openbaoPlugins.secrets-aws

OpenBao secrets plugin to generate AWS access credentials based on IAM policies

  • nixos-unstable -
    • nixos-unstable-small 0.3.1

pkgs.openbaoPlugins.secrets-gcp

OpenBao secrets plugin to generate GCP service account keys and OAuth tokens based on IAM policies

  • nixos-unstable -

pkgs.openbaoPlugins.secrets-azure

OpenBao secrets plugin to generate Azure service principals with role and group assignments

  • nixos-unstable -

Package maintainers

Untriaged
created 5 months ago Activity log
  • Created suggestion
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is addressed in v2.5.3.

Affected products

openbao
  • ==< 2.5.3

Matching in nixpkgs

pkgs.openbao

Open source, community-driven fork of Vault managed by the Linux Foundation

  • nixos-unstable -
    • nixos-unstable-small 2.7.0
  • nixos-26.05 -
    • nixos-26.05-small 2.6.2

pkgs.openbaoPlugins.auth-gcp

OpenBao auth plugin to authenticate using Google Cloud Platform credentials

  • nixos-unstable -

pkgs.openbaoPlugins.secrets-aws

OpenBao secrets plugin to generate AWS access credentials based on IAM policies

  • nixos-unstable -
    • nixos-unstable-small 0.3.1

pkgs.openbaoPlugins.secrets-gcp

OpenBao secrets plugin to generate GCP service account keys and OAuth tokens based on IAM policies

  • nixos-unstable -

pkgs.openbaoPlugins.secrets-azure

OpenBao secrets plugin to generate Azure service principals with role and group assignments

  • nixos-unstable -

Package maintainers