The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 19:17
Updated : 2026-09-10 20:17
NVD link : CVE-2026-87993
Mitre link : CVE-2026-87993
CVE.ORG link : CVE-2026-87993
JSON object : View
Products Affected
No product.
CWE
CWE-532
Insertion of Sensitive Information into Log File
