CVE-2026-87993

    Dashboard / Vulnerabilities / CVE-2026-87993

    CVE-2026-87993

    Published: 10 Sept 2026Last Modified: 11 Sept 2026

    Summary: Consul-template vulnerable to an information disclosure issue in error handling

    Details: The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 0400fa21081d44bd8aeccf858f093c2fe13d7774

    Affected versions

    v0.42.1
    v0.42.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-87993 | CVE-DB