CVE-2024-12289
Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.38%
- CWE
- CWE-460
- Published
- 2024-12-12
- Last modified
- 2026-03-13
Affected products
- HashiCorp Boundary
- HashiCorp Boundary Enterprise
Weakness type
Related vulnerabilities
- CVE-2026-86748 — Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
- CVE-2026-61387 — In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not...
- CVE-2026-48524 — PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2026-33481 — Syft improper temporary file cleanup
- CVE-2026-20118 — Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability
- CVE-2025-59399 — libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is...
- CVE-2025-32439 — pleezer allows resource exhaustion through uncollected hook script processes