SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14362

MEDIUM · CVSS 4.9 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

HashiCorp memberlist versions prior to 0.6.0 are susceptible to a denial-of-service vulnerability that can be exploited by an attacker with network access to the gossip port, potentially leading to memory exhaustion and process termination on affected nodes. Organizations using this software should prioritize upgrading to version 0.6.0 or later to mitigate the risk of service disruption.

CVE
CVE-2026-14362
Severity
MEDIUM
CVSS
4.9
EPSS
0.25%

Original NVD Description

HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.