CVE-2026-7776 Details
Description
Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate worker connections from being accepted or routed. This vulnerability, CVE-2026-7776, is fixed in Boundary 0.21.3, 0.20.3, 0.19.5.
A denial-of-service vulnerability has been identified in HashiCorp Boundary Community Edition and Boundary Enterprise workers, prior to versions 0.21.3, 0.20.3, and 0.19.5. The issue arises during node enrollment TLS handshakes, where an attacker with network access to the worker authentication listener can delay or withhold the client certificate. This disruption causes the connection handling to block, potentially preventing legitimate worker connections from being accepted or routed.
Users are advised to upgrade to HashiCorp Boundary Community Edition or Boundary Enterprise versions 0.21.3, 0.20.3, or 0.19.5. For guidance on upgrading, please refer to Boundary's upgrade documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 4, 2026CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2026-11-boundary-workers-vulnerable-to-denial-of-service-during-tls-handshake | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HashiCorp Boundary | <= 0.21.2 (semver) <= 0.20.2 (semver) <= 0.19.4 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | New CVE Received | [email protected] |
Volerion