Junglewise Threat Intelligence

CVE-2026-87993: HashiCorp Consul-template information disclosure in error handling

CVE-2026-87993 · Severity: high · CVSS 7.7 · Published 2026-09-10

Technologies: HashiCorp Consul-Template. Vendors: HashiCorp.

Executive brief

Consul-template is a tool that automatically renders Vault secrets into configuration files for applications and infrastructure. A flaw in its error handling causes secret values to leak into error messages and logs instead of being redacted. Attackers with access to logs or systems using Nomad can view these exposed secrets, potentially compromising sensitive credentials and enabling unauthorized access to protected systems.

Technical details

The vulnerability is an information disclosure issue in the secret redaction mechanism of consul-template's error handling path. When template expressions fail to render, the library attempts to redact Vault secret values from error messages before logging or returning them to callers; however, the redaction logic fails to handle all Vault secret response shapes, allowing certain secret field values to escape redaction and appear verbatim in error output. The affected versions (0.27.2 through 0.42.1) are vulnerable when using Vault KV v2 secrets; deployments using only KV v1 secrets are unaffected. Error messages can be written to application logs and, when consul-template integrates with Nomad, exposed in task events accessible to users with job-read permissions. The fix is available in consul-template 0.43.0.

Affected products

  • HashiCorp Consul-template 0.27.2 through 0.42.1

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: patched: Fixed in consul-template 0.43.0

References

Related threats