Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c56-jfhx-4gcm

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.7

Описание

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

EPSS

Процентиль: 24%
0.00317
Низкий

8.7 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.7
ubuntu
около 2 месяцев назад

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

CVSS3: 8.7
nvd
около 2 месяцев назад

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

CVSS3: 8.7
debian
около 2 месяцев назад

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escap ...

EPSS

Процентиль: 24%
0.00317
Низкий

8.7 High

CVSS3

Дефекты

CWE-59