Impact
HashiCorp memberlist before version 0.6.0 contains a flaw in its push/pull state handling that allows an attacker to send a crafted gossip message. The vulnerable code can deplete the receiving node’s memory, causing the memberlist process to terminate and the node to become inoperative.
Affected Systems
The vulnerability affects HashiCorp memberlist versions prior to 0.6.0. Any deployment using the shared library in these releases is potentially exposed.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity impact. The EPSS score is < 1%, indicating a very low exploitation probability. While no exploitation data is available and the vulnerability is not listed in CISA KEV, the attack vector is inferred to be network‑based, requiring an attacker to access the gossip port. An adversary who can reach that port can trigger memory exhaustion to cause a denial of service on the target node.
OpenCVE Enrichment