Consul-Template 0.43.0: Prevent Vault Secrets Leak via Error Handling
CVE-2026-87993 Published on September 10, 2026

Consul-template vulnerable to an information disclosure issue in error handling
The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0.

NVD

Weakness Type

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.


Affected Versions

HashiCorp Tooling: