Description

Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate worker connections from being accepted or routed. This vulnerability, CVE-2026-7776, is fixed in Boundary 0.21.3, 0.20.3, 0.19.5.

INFO

Published Date :

2026-05-04T21:34:10.975Z

Last Modified :

2026-05-05T14:14:05.799Z

Source :

HashiCorp
AFFECTED PRODUCTS

The following products are affected by CVE-2026-7776 vulnerability.

Vendors Products
Hashicorp
  • Boundary
  • Boundary Enterprise
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-7776.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact