GHSA-9fmc-5fq4-5jwh
GitHub Security Advisory
HashiCorp Nomad vulnerable to Insufficient Session Expiration
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
Affected Packages
Go
github.com/hashicorp/nomad
Affected versions:
1.4.0
(fixed in 1.4.2)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.