Description
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.
Published: 2026-07-08
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HashiCorp memberlist before version 0.6.0 contains a flaw in its push/pull state handling that allows an attacker to send a crafted gossip message. The vulnerable code can deplete the receiving node’s memory, causing the memberlist process to terminate and the node to become inoperative.

Affected Systems

The vulnerability affects HashiCorp memberlist versions prior to 0.6.0. Any deployment using the shared library in these releases is potentially exposed.

Risk and Exploitability

The CVSS score of 4.9 indicates a moderate severity impact. The EPSS score is < 1%, indicating a very low exploitation probability. While no exploitation data is available and the vulnerability is not listed in CISA KEV, the attack vector is inferred to be network‑based, requiring an attacker to access the gossip port. An adversary who can reach that port can trigger memory exhaustion to cause a denial of service on the target node.

Generated by OpenCVE AI on July 26, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to memberlist 0.6.0 or later to eliminate the memory exhaustion bug.
  • Configure firewall rules to restrict access to the gossip port only to trusted internal hosts, limiting the potential for an usage and set alerts for sudden spikes, which may indicate an attempted denial‑of‑service attack.
  • Monitor the memberlist process memory usage and set alerts for abnormal consumption patterns.

Generated by OpenCVE AI on July 26, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp shared Library
Vendors & Products Hashicorp
Hashicorp shared Library

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.
Title Denial of service via crafted push/pull gossip message in memberlist
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Hashicorp Shared Library
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-07-08T19:40:16.119Z

Reserved: 2026-07-01T19:07:40.964Z

Link: CVE-2026-14362

cve-icon Vulnrichment

Updated: 2026-07-08T18:29:57.500Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-08T17:14:18Z

Links: CVE-2026-14362 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T17:30:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling