CVE-2026-14362
published 2026-07-08CVE-2026-14362: HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.44%
36.9th percentile
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hashicorp | shared_library | >= 0.1.5 < 0.6.0 | 0.6.0 |
| openshift4 | metallb-rhel8 | — | — |
| openshift4 | metallb-rhel9 | — | — |
| openshift4 | ose-prometheus-alertmanager | — | — |
| openshift4 | ose-prometheus-alertmanager-rhel9 | — | — |
| rhacm2 | prometheus-alertmanager-rhel9 | — | — |
| rhceph | alloy-rhel10 | — | — |
| rhceph | grafana-rhel10 | — | — |
| rhceph | rhceph-5-dashboard-rhel8 | — | — |
| rhceph | rhceph-6-dashboard-rhel9 | — | — |
| rhceph | rhceph-promtail-rhel9 | — | — |
| rhceph | snmp-notifier-rhel10 | — | — |
| rhceph | snmp-notifier-rhel8 | — | — |
| rhceph | snmp-notifier-rhel9 | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling
vendor_redhat·2026-07-08·CVSS 4.9
CVE-2026-14362 [MEDIUM] CWE-770 github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling
github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.
A flaw was found in HashiCorp memberlist. An attacker with network access to the gossip port could exploit a vulnerability in the push/pull state handling. This could lead to memory exhaustion on a receiving node, causing the process to terminate. This flaw results in a Denial of Service (DoS).
Statement: Only Red Hat products that run the affected component as a live m
GHSA
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory
ghsa_unreviewed·2026-07-08·CVSS 4.9
CVE-2026-14362 [MEDIUM] CWE-770 HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.
No detection rules found.
No public exploits indexed.
2026-07-08
Published