CVE lookup
CVE-2026-14891
Pruva has a verified reproduction for CVE-2026-14891: HashiCorp Nomad's Docker task driver can be tricked into bind-mounting host paths via a symlink containment bypass, enabling sandbox escape and host file read/write.. The canonical evidence record is REPRO-2026-00385.
REPRO
REPRO-2026-00385
Package
hashicorp/nomad · other
Severity
HIGH
Status
published