Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.54% | — | TerragruntAIOpentofuAIHashicorp TerraformAI | 21/8/2026 | 25/9/2026 | Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .terragrunt-module-manifest during fileManifest.Clean() in internal/util/file.go. A malicious or compromised external… | |
| Aplazada | Media (5.9) | 0.50% | — | InfracostAIHashicorp TerraformAIHashicorp Terraform CloudAI | 21/8/2026 | 18/9/2026 | Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a configured Terraform Cloud or registry token to a destination hostname derived… | |
| Aplazada | Crítica (10) | 0.46% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in… | |
| Aplazada | Alta (8.9) | 0.36% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed… | |
| Aplazada | Alta (8.6) | 0.39% | — | Terraform-mcp-serverAI | 28/7/2026 | 30/7/2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This… | |
| Pendiente de análisis | Alta (8.8) | 0.53% | — | Snowflake Terraform ProviderAI | 8/7/2026 | 9/7/2026 | Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data source input could result in arbitrary SQL execution under the provider's privileged Snowflake session, potentially enabling sensitive data exfiltration and minting of… | |
| Aplazada | Alta (7.7) | 0.44% | — | Hashicorp Terraform EnterpriseAI | 6/7/2026 | 7/7/2026 | HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module content. This may allow an authenticated user to include files from outside the intended repository content in a module and then… | |
| Pendiente de análisis | Crítica (9.2) | 0.41% | — | Google Cloud Alloydb FOR PostgresqlAIHashicorp TerraformAI | 12/5/2026 | 17/6/2026 | Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database. Exploitation required network access to the… | |
| Analizada | Alta (7.7) | 0.58% | — | Terraform Linode Provider | 26/2/2026 | 17/6/2026 | The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by default. This issue is exposed when debug/provider logs are explicitly enabled (for… | |
| Analizada | Alta (8.7) | 0.55% | — | BPG Terraform Provider | 4/2/2026 | 17/6/2026 | Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure and can result in escaping the folder using ../, allowing any files on the system to be edited. This issue has been patched in version… | |
| Analizada | Media (4.3) | 0.18% | — | Hashicorp Terraform | 21/11/2025 | 17/6/2026 | Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is… | |
| Analizada | Crítica (9.8) | 0.53% | — | Hashicorp Terraform Provider | 21/11/2025 | 17/6/2026 | Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability,… | |
| Aplazada | Baja (1.1) | 0.56% | — | Terraform Windns ProviderAI | 6/5/2025 | 17/6/2026 | Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. This could lead to authenticated command injection in the… | |
| Analizada | Alta (8.8) | 1.6% | — | Microsoft Power Platform Terraform Provider | 25/9/2024 | 17/6/2026 | Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the service principal authentication, may be exposed in logs.… | |
| Modificada | Alta (7.8) | 0.27% | — | Hashicorp Terraform | 8/9/2023 | 17/6/2026 | Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7. | |
| Modificada | Media (6.5) | 0.96% | — | Weave Gitops Terraform Controller | 14/7/2023 | 17/6/2026 | Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave GitOps Terraform Controller which could allow an authenticated remote attacker to view sensitive information. This vulnerability stems from… | |
| Modificada | Alta (7.7) | 0.42% | — | Hashicorp Terraform Enterprise | 22/6/2023 | 17/6/2026 | Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged workspace in the same organization that… | |
| Modificada | Baja (3.3) | 0.21% | — | Kitchen-terraform Project Kitchen-terraform | 21/4/2023 | 17/6/2026 | Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform configuration and verify the resulting infrastructure systems with InSpec controls. Kitchen-Terraform v7.0.0 introduced a regression which caused all Terraform output values, including sensitive… | |
| Modificada | Alta (7.5) | 0.96% | — | Hashicorp Terraform Enterprise | 25/2/2022 | 17/6/2026 | HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1. | |
| Modificada | Alta (8.8) | 0.97% | — | Hashicorp Terraform Enterprise | 15/9/2021 | 17/6/2026 | HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration. Fixed in v202109-1. | |
| Modificada | Alta (8.8) | 0.95% | — | Hashicorp Terraform | 20/7/2021 | 17/6/2026 | HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hashicorp Terraform Provider | 22/4/2021 | 17/6/2026 | HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1. | |
| Modificada | Media (6.5) | 0.65% | — | Hashicorp Terraform Enterprise | 26/3/2021 | 17/6/2026 | HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1. | |
| Modificada | Media (5.3) | 0.85% | — | Hashicorp Terraform Enterprise | 30/7/2020 | 17/6/2026 | HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1. | |
| Modificada | Alta (7.5) | 1.00% | — | Hashicorp Terraform | 2/12/2019 | 17/6/2026 | When using the Azure backend with a shared access signature (SAS), Terraform versions prior to 0.12.17 may transmit the token and state snapshot using cleartext HTTP. |