RepoJournal
HashiCorp

@hashicorp

Terraform, Vault, Consul - infra-as-code for ops teams

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

One email a day. Unsubscribe in one click.

Pick a date

Topics: Go Infrastructure Full archive →

The Wire · Showcase

CONSUL-K8S PATCHES TORNADO COOKIE INJECTION FLAW

By RepoJournal · Filed · About HashiCorp

Consul-K8s shipped an emergency security fix overnight for a cookie attribute injection vulnerability in Tornado that could expose your gateway API layer.

Consul-K8s upgraded Tornado from 6.3.2 to 6.5.5 to patch GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) [1], a CWE-159 improper input handling flaw that allows attackers to inject malicious cookie attributes. This affects the control-plane gateway API stack and hits your security boundary if you're running Consul service mesh on Kubernetes. The fix is already merged [2] — it's a straightforward dependency bump with no breaking changes. Meanwhile, three nightly snapshots dropped across the Nomad ecosystem [3][4][5], but these are development builds for testing only and not recommended for production. The real story is Consul-K8s: patch before your next gateway deployment.

One email a day. Unsubscribe in one click.

Action items

References

  1. [1] security: upgrade tornado 6.3.2 -> 6.5.5 to fix GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) (#5297) hashicorp/consul-k8s
  2. [2] security: upgrade tornado 6.3.2 -> 6.5.5 to fix GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) ↗ hashicorp/consul-k8s
  3. [3] nightly ↗ hashicorp/nomad-driver-podman
  4. [4] nightly ↗ hashicorp/nomad-autoscaler
  5. [5] nightly ↗ hashicorp/nomad-pack

Quick answers

What shipped in HashiCorp on May 9, 2026?
Consul-K8s shipped an emergency security fix overnight for a cookie attribute injection vulnerability in Tornado that could expose your gateway API layer. In total, 1 commits, 1 pull requests, and 3 releases landed.
Who contributed to HashiCorp on May 9, 2026?
1 developer shipped this update, including Surabhi-1605.
What were the notable HashiCorp updates?
security: upgrade tornado 6.3.2 -> 6.5.5 to fix GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) (#5297), security: upgrade tornado 6.3.2 -> 6.5.5 to fix GHSA-fqwm-6jpj-5wxc (CVE-2026-35536), and nightly.

More from @hashicorp

Daily updates, in your inbox

Follow HashiCorp

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

One email a day. Unsubscribe in one click. Read a past issue →

Elsewhere on the wire

Want every project, not just this one?