GHSA-7x9r-wcgg-w86f

Suggest an improvement
Source
https://github.com/advisories/GHSA-7x9r-wcgg-w86f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7x9r-wcgg-w86f/GHSA-7x9r-wcgg-w86f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7x9r-wcgg-w86f
Aliases
  • CVE-2026-7776
Published
2026-05-05T00:30:22Z
Modified
2026-05-08T19:16:33.726865Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
Details

Boundary Community Edition and Boundary Enterprise ("Boundary") workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate worker connections from being accepted or routed. This vulnerability, CVE-2026-7776, is fixed in Boundary 0.21.3, 0.20.3, 0.19.5.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-08T19:01:54Z",
    "nvd_published_at": "2026-05-04T22:16:20Z",
    "severity": "HIGH"
}
References

Affected packages

Go / github.com/hashicorp/boundary

Package

Name
github.com/hashicorp/boundary
View open source insights on deps.dev
Purl
pkg:golang/github.com/hashicorp/boundary

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.19.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7x9r-wcgg-w86f/GHSA-7x9r-wcgg-w86f.json"

Go / github.com/hashicorp/boundary

Package

Name
github.com/hashicorp/boundary
View open source insights on deps.dev
Purl
pkg:golang/github.com/hashicorp/boundary

Affected ranges

Type
SEMVER
Events
Introduced
0.20.0
Fixed
0.20.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7x9r-wcgg-w86f/GHSA-7x9r-wcgg-w86f.json"

Go / github.com/hashicorp/boundary

Package

Name
github.com/hashicorp/boundary
View open source insights on deps.dev
Purl
pkg:golang/github.com/hashicorp/boundary

Affected ranges

Type
SEMVER
Events
Introduced
0.21.0
Fixed
0.21.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7x9r-wcgg-w86f/GHSA-7x9r-wcgg-w86f.json"