CVE-2022-41606EPSS p50.9%
CVE-2022-41606CVE-2022-41606
hashicorp / nomad
Description
HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.74% probability of exploitation · percentile 50.9% · 2026-08-03T12:00:16Z |
| Last modified | 2026-06-17 |