GHSA-8449-7gc2-pwrp · Severity: high · Ecosystem: go — HashiCorp Consul Template could reveal Vault secret contents in error messages
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.
Conclusion & alert: CVE-2022-38149 is rated Moderate Risk (46.8/100): CVSS High severity, with low exploitation likelihood (EPSS 0.69%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.60% | 0.69% | +0.09% |
| 2 | 2026-06-08 | 0.39% | 0.60% | +0.21% |
| 3 | 2025-11-21 | — | 0.39% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-8449-7gc2-pwrp · Severity: high · Ecosystem: go — HashiCorp Consul Template could reveal Vault secret contents in error messages
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2022-38149: 1 source package rows (consul-template); 7 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 0. | https://security.alpinelinux.org/vuln/CVE-2022-38149 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2022-38149 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| hashicorp | consul_template | < 0.29.2 | cpe:2.3:a:hashicorp:consul_template:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://discuss.hashicorp.com | Vendor Advisory |
| https://discuss.hashicorp.com/t/hsec-2022-16-consul-template-may-expose-vault-secrets-when-processing-invalid-input/43215 | Vendor Advisory |