VYPR
Moderate severityNVD Advisory· Published Feb 16, 2023· Updated Mar 18, 2025

Nomad Client Vulnerable to Decompression Bombs in Artifact Block

CVE-2023-0821

Description

HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

HashiCorp Nomad clients are vulnerable to a decompression bomb attack via maliciously crafted artifact stanzas in jobs.

Vulnerability

Analysis

CVE-2023-0821 is a denial-of-service (DoS) vulnerability in HashiCorp Nomad and Nomad Enterprise affecting versions 1.2.15 through 1.3.8, and 1.4.3. The vulnerability lies in the artifact stanza processing, where Nomad uses the go-getter library to fetch and decompress job artifacts. A maliciously compressed source, known as a 'Zip Bomb,' can be included in the artifact stanza of a submitted job, causing the Nomad client agent to consume excessive disk resources during decompression [1][2].

Exploitation

Method

An attacker must have authenticated access to the Nomad cluster with the ability to submit jobs. By crafting a job specification that references a maliciously compressed artifact, the attacker triggers uncontrolled decompression on the client agent. This does not require any privilege escalation beyond the submit-job capability, and the attack is executed simply by the client agent processing the artifact as part of job allocation [2].

Impact and

Mitigation

The primary impact is a denial-of-service condition: excessive disk usage can crash the Nomad client agent, disrupting workloads scheduled on that node. HashiCorp has addressed this by modifying the go-getter usage to allow administrators to set decompression limits via the client agent configuration options artifact.decompression_size_limit and artifact.decompression_file_count_limit [2]. The fix is included in Nomad versions 1.2.16, 1.3.9, and 1.4.4. Operators are strongly advised to upgrade to these patched versions or apply the configuration limits as a workaround [1][2].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/hashicorp/nomadGo
>= 1.2.15, < 1.2.161.2.16
github.com/hashicorp/nomadGo
>= 1.3.0, < 1.3.91.3.9
github.com/hashicorp/nomadGo
>= 1.4.0, < 1.4.41.4.4

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.