CVE-2026-14362: Denial of service via crafted push/pull gossip message in memberlist
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp memberlistto a version that resolves this vulnerability.Fixed in 0.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14362?
CVE-2026-14362 has a medium severity rating of 4.9.
What type of vulnerability is CVE-2026-14362?
CVE-2026-14362 is a denial-of-service vulnerability in HashiCorp memberlist.
How do I fix CVE-2026-14362?
To mitigate CVE-2026-14362, upgrade HashiCorp memberlist to version 0.6.0 or later.
What is affected by CVE-2026-14362?
CVE-2026-14362 affects HashiCorp memberlist versions prior to 0.6.0.
Who can exploit CVE-2026-14362?
An attacker with network access to the gossip port can exploit CVE-2026-14362.