cbcvebase.
CVE-2026-14362
published 2026-07-08

CVE-2026-14362: HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network…

PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.44%
36.9th percentile
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.

Affected

14 ranges
VendorProductVersion rangeFixed in
hashicorpshared_library>= 0.1.5 < 0.6.00.6.0
openshift4metallb-rhel8
openshift4metallb-rhel9
openshift4ose-prometheus-alertmanager
openshift4ose-prometheus-alertmanager-rhel9
rhacm2prometheus-alertmanager-rhel9
rhcephalloy-rhel10
rhcephgrafana-rhel10
rhcephrhceph-5-dashboard-rhel8
rhcephrhceph-6-dashboard-rhel9
rhcephrhceph-promtail-rhel9
rhcephsnmp-notifier-rhel10
rhcephsnmp-notifier-rhel8
rhcephsnmp-notifier-rhel9

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.