HashiCorp Nomad vulnerable to symlink attack
Moderate severity
GitHub Reviewed
Published
May 12, 2026
to the GitHub Advisory Database
•
Updated May 19, 2026
Package
Affected versions
< 1.11.0-rc.1.0.20260512123500-2a09fd62c238
Patched versions
1.11.0-rc.1.0.20260512123500-2a09fd62c238
Description
Published by the National Vulnerability Database
May 12, 2026
Published to the GitHub Advisory Database
May 12, 2026
Reviewed
May 19, 2026
Last updated
May 19, 2026
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
References