highCVSS 7.5Vulnerability

CVE-2026-7776

Boundary Community Edition and Boundary Enterprise ("Boundary") workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate worker connections from being accepted or routed. This vulnerability, CVE-2026-7776, is fixed in Boundary 0.21.3, 0.20.3, 0.19.5.

Properties

summary
Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
severity
high
epss_score
0.002
cvss_score
7.5
ghsa_published
2026-05-05T00:30:22Z
source_url
https://github.com/advisories/GHSA-7x9r-wcgg-w86f
ghsa_updated
2026-05-08T19:01:56Z
ghsa_id
GHSA-7x9r-wcgg-w86f
cve_id
CVE-2026-7776
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.10234

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/hashicorp/boundary

AFFECTS (1)

[Software]go/github.com/hashicorp/boundary

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7776 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal