High severity7.5NVD Advisory· Published May 4, 2026· Updated May 5, 2026
CVE-2026-7776
CVE-2026-7776
Description
Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate worker connections from being accepted or routed. This vulnerability, CVE-2026-7776, is fixed in Boundary 0.21.3, 0.20.3, 0.19.5.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/hashicorp/boundaryGo | < 0.19.5 | 0.19.5 |
github.com/hashicorp/boundaryGo | >= 0.20.0, < 0.20.3 | 0.20.3 |
github.com/hashicorp/boundaryGo | >= 0.21.0, < 0.21.3 | 0.21.3 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
32- PoC Code Published for Critical NGINX VulnerabilitySecurityWeek · May 16, 2026
- Deepfake detection is losing ground to generative modelsHelp Net Security · May 15, 2026
- White House cyber official: identity security matters more than ever in the age of AICyberScoop · May 14, 2026
- The time of much patching is comingCisco Talos Intelligence · May 14, 2026
- F5 Patches Over 50 VulnerabilitiesSecurityWeek · May 14, 2026
- AWS to Quick admins: The access control didn't work, but you weren't using it anyway, so what's the problem?The Register Security · May 13, 2026
- May 2026 Patch Tuesday: no zero-days but plenty to fixMalwarebytes Labs · May 13, 2026
- When "idle" isn't idle: how a Linux kernel optimization became a QUIC bugCloudflare Blog · May 12, 2026
- Copy.Fail Linux VulnerabilitySchneier on Security · May 12, 2026
- TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain AttackSecurityWeek · May 12, 2026
- State-sponsored actors, better known as the friends you don’t wantCisco Talos Intelligence · May 12, 2026
- Cline Kanban Flaw Lets Websites Hijack AI Coding AgentsInfosecurity Magazine · May 7, 2026
- Copy Fail: What You Need to Know About the Most Severe Linux Threat in YearsUnit 42 · May 5, 2026
- Pipelock: Open-source AI agent firewallHelp Net Security · May 4, 2026
- Introducing Dynamic Workflows: durable execution that follows the tenantCloudflare Blog · May 1, 2026
- VECT: Ransomware by design, Wiper by accidentCheck Point Research · Apr 28, 2026
- Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks AboutThe Hacker News · Apr 28, 2026
- Parsing Agentic Offensive Security's Existential ThreatDark Reading · Apr 27, 2026
- Researchers Uncover 10 In-the-Wild Prompt Injection Payloads Targeting AI AgentsInfosecurity Magazine · Apr 23, 2026
- Hypersonic Supply Chain Attacks: One Solution That Didn’t Need to Know the PayloadSentinelOne Labs · Apr 22, 2026
- Making Rust Workers reliable: panic and abort recovery in wasm‑bindgenCloudflare Blog · Apr 22, 2026
- World-first NCSC-engineered device secures vulnerable display linksNCSC UK · Apr 22, 2026
- Exploits Turn Windows Defender Into Attacker ToolDark Reading · Apr 21, 2026
- Google Fixes Critical RCE Flaw in AI-Based 'Antigravity' ToolDark Reading · Apr 21, 2026
- Orchestrating AI Code Review at scaleCloudflare Blog · Apr 20, 2026
- Attackers Actively Exploiting Critical Vulnerability in Ninja Forms – File Upload PluginWordfence Blog · Apr 16, 2026
- Securing the Software Supply Chain: How SentinelOne’s AI EDR Autonomously Blocked the CPU-Z Watering Hole Cyber AttackSentinelOne Labs · Apr 14, 2026
- Edge Decay: How a Failing Perimeter Is Fueling Modern IntrusionsSentinelOne Labs · Apr 9, 2026
- ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution RuntimeCheck Point Research · Mar 30, 2026
- Cloud workload security: Mind the gapsESET WeLiveSecurity · Mar 24, 2026
- Siemens SIMATICCISA Alerts
- May 2026 Patch Tuesday: 30 Critical Vulnerabilities Among 130 CVEsCrowdStrike Blog