---
name: HashiCorp
slug: hashicorp
domain: hashicorp.com
category: infrastructure
sources: 11
total_releases: 1257
releases_last_30d: 14
avg_releases_per_week: 3.9
last_updated: 2026-07-19
tracking_since: 2019-08-15
canonical: https://releases.sh/hashicorp
overview_url: https://releases.sh/hashicorp/overview.md
tags:
  - consul
  - terraform
  - vault
aliases:
  - terraform.io
accounts:
  github: "hashicorp"
  x: "HashiCorp"
  youtube: "@hashicorp"
---

## Overview

Recently shipped Nomad CVE fixes, Terraform 1.16 alpha on_failure triggers, and HCP Vault 2.0.3 on AWS and Azure.

**Nomad 2.0.4 and enterprise releases patched three security vulnerabilities.** CVE-2026-14891 and CVE-2026-14896 addressed Docker container escape paths: host namespace mode enforcement and symlink-bypass plugin configuration. A namespace-crossing bug in dynamic host volume deletion was also fixed. Consul service, template, and connect blocks can now fall back to the client agent's Consul token when workload identity is unavailable. The `nomad setup vault` CLI gained a `-kv-path` flag for the generated workload policy's Vault KV mount. [source: https://github.com/hashicorp/nomad/releases/tag/v2.0.4] [source: https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.11.8] [source: https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.10.14]

**Terraform's 1.16 alpha track added resource action `on_failure` modes.** Resources using `create_before_destroy` or other action triggers can now specify `halt`, `taint`, or `continue` on failure. The alpha also shipped the `store` block in `terraform_data` for ephemeral and sensitive values, provider support for nested blocks as computed values, and `import` blocks inside modules. The 1.15 stable line saw 1.15.8, fixing a `terraform init` error with service-discovery aliases from the configured backend. [source: https://github.com/hashicorp/terraform/releases/tag/v1.16.0-alpha20260708] [source: https://github.com/hashicorp/terraform/releases/tag/v1.15.8]

**Consul 2.0.2 upgraded Alpine base and hardened Envoy inbound listeners.** Alpine moved to 3.24 to address CVEs. Envoy inbound public listeners now return errors when injection of the L4 intention filter or mTLS transport socket fails, preventing listeners served without intention enforcement or mTLS. Enterprise-only external processor (ext_proc) Envoy extension support was added to api-gateway and connect-proxy config entries. [source: https://github.com/hashicorp/consul/releases/tag/v2.0.2]

<Product name="Consul" slug="consul" sources="1" url="https://github.com/hashicorp/consul" canonical="https://releases.sh/hashicorp/consul" />
<Product name="HCP" slug="hcp" sources="1" url="https://developer.hashicorp.com/hcp" canonical="https://releases.sh/hashicorp/hcp" />
<Product name="Nomad" slug="nomad" sources="1" url="https://github.com/hashicorp/nomad" canonical="https://releases.sh/hashicorp/nomad" />
<Product name="Terraform" slug="terraform" sources="1" canonical="https://releases.sh/hashicorp/terraform" />
<Product name="Vault" slug="vault" sources="1" canonical="https://releases.sh/hashicorp/vault" />

<Source name="Boundary" slug="boundary" type="github" releases="78" latest-version="v0.21.3" latest-date="2026-04-30T15:23:16.000Z" url="https://releases.sh/hashicorp/boundary" />
<Source name="CDK for Terraform" slug="cdk-for-terraform" type="github" releases="100" latest-version="v0.21.0" latest-date="2025-06-04T16:46:50.000Z" url="https://releases.sh/hashicorp/cdk-for-terraform" />
<Source name="Consul" slug="consul" type="github" releases="106" latest-version="v2.0.2" latest-date="2026-07-08T10:39:04.000Z" url="https://releases.sh/hashicorp/consul" />
<Source name="HCP Changelog" slug="hcp-changelog" type="scrape" releases="265" latest-version="2.0.3" latest-date="2026-07-07T00:00:00.000Z" url="https://releases.sh/hashicorp/hcp-changelog" />
<Source name="Nomad" slug="nomad" type="github" releases="116" latest-version="ent-changelog-1.11.8" latest-date="2026-07-08T16:53:09.000Z" url="https://releases.sh/hashicorp/nomad" />
<Source name="Packer" slug="packer" type="github" releases="64" latest-version="v1.15.1" latest-date="2026-03-26T13:11:53.000Z" url="https://releases.sh/hashicorp/packer" />
<Source name="Terraform" slug="terraform" type="github" releases="123" latest-version="v1.16.0-alpha20260715" latest-date="2026-07-15T12:44:36.000Z" url="https://releases.sh/hashicorp/terraform" />
<Source name="Terraform Provider AWS" slug="terraform-provider-aws" type="github" releases="100" latest-version="v6.39.0" latest-date="2026-04-01T20:12:59.000Z" url="https://releases.sh/hashicorp/terraform-provider-aws" />
<Source name="Terraform Provider AzureRM" slug="terraform-provider-azurerm" type="github" releases="100" latest-version="v4.67.0" latest-date="2026-04-02T20:14:00.000Z" url="https://releases.sh/hashicorp/terraform-provider-azurerm" />
<Source name="Vagrant" slug="vagrant" type="github" releases="101" latest-version="2.4.10.dev+000781-f9e2630d" latest-date="2026-04-09T05:59:06.000Z" url="https://releases.sh/hashicorp/vagrant" />
<Source name="Vault" slug="vault" type="github" releases="104" latest-version="v2.0.3" latest-date="2026-06-17T20:23:38.000Z" url="https://releases.sh/hashicorp/vault" />

## Recent Releases

_Summaries below — fetch the release's `canonical` URL for full content, or `url` for the original source._

<Release source="terraform" version="v1.15.8" date="July 8, 2026" published="2026-07-08T17:45:09.000Z" url="https://github.com/hashicorp/terraform/releases/tag/v1.15.8" canonical="https://releases.sh/release/rel_abe3TFTeZpLbBBPdnA1Va" truncated="true">
Fixed terraform init error when installing providers sourced from a service-discovery alias advertised by the configured backend. Provider installation order and logging were adjusted to support future enhancements, with module installation now occurring after backend initialization.
</Release>

<Release source="nomad" version="ent-changelog-1.11.8" date="July 8, 2026" published="2026-07-08T16:53:09.000Z" url="https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.11.8" canonical="https://releases.sh/release/rel_PztcJAfwhvBMSHKnANjW_" truncated="true">
### v1.11.8 (Enterprise)

Fixed two Docker security issues: enforcement of allowed_modes or allow_privileged requirement for host namespace modes (CVE-2026-14891), and a symlink bypass of the volumes.enabled=false plugin configuration (CVE-2026-14896). Also fixed a cross-namespace host volume deletion bug and several scheduler issues affecting sticky volumes and feasibility checking.
</Release>

<Release source="nomad" version="ent-changelog-1.10.14" date="July 8, 2026" published="2026-07-08T16:31:37.000Z" url="https://github.com/hashicorp/nomad/releases/tag/ent-changelog-1.10.14" canonical="https://releases.sh/release/rel_mJuRhbNhwaKAVtfoZaBUr" truncated="true">
### v1.10.14 (Enterprise)

Fixed two Docker security issues: CVE-2026-14891 enforces allowed_modes or allow_privileged requirement for host namespace modes, and CVE-2026-14896 closes a symlink bypass for volumes.enabled=false. Also fixed a cross-namespace host volume deletion vulnerability and multiple scheduler and UI bugs including a ModifyIndex collision that omitted jobs from the jobs page.
</Release>

<Release source="consul" version="v2.0.2" date="July 8, 2026" published="2026-07-08T10:39:04.000Z" url="https://github.com/hashicorp/consul/releases/tag/v2.0.2" canonical="https://releases.sh/release/rel_dl_ogVCcSHjQLGzMnkhXd" truncated="true">
Upgraded Alpine base image to 3.24 to address CVE-2026-41989 and ALPINE-CVE-2026-2100, and upgraded Serf and Memberlist to their latest versions. XDS now returns errors when injecting L4 intention (RBAC) filter or mTLS transport socket onto inbound public listeners without enforcement, preventing listeners from being served without intention enforcement or mTLS. Also added ExtAuthzFilter support to HTTPRoute Filters and gateway-wide ExtAuthz toggle for api-gateway (Enterprise only), and External Processor (ext_proc) Envoy Extension support for api-gateway and connect-proxy (Enterprise only).
</Release>

<Release source="nomad" version="v2.0.4" date="July 7, 2026" published="2026-07-07T19:12:06.000Z" url="https://github.com/hashicorp/nomad/releases/tag/v2.0.4" canonical="https://releases.sh/release/rel_VgbpPluxs63m-FO9Xs0tP" truncated="true">
Fixed a security bug where users with `host-volume-delete` permission in one namespace could delete claims from another namespace. Also fixed scheduler issues with sticky host volumes, a client panic after allocation garbage collection, and UI rendering of jobs with matching ModifyIndex values.
</Release>

<Release source="hcp-changelog" version="2.0.3" date="July 7, 2026" published="2026-07-07T00:00:00.000Z" url="https://developer.hashicorp.com/hcp/docs/changelog#2-0-3" canonical="https://releases.sh/release/rel_eWxX26Osxd7_IST7MPgxH" truncated="true">
### HCP Vault 2.0.3 for AWS and Azure

Vault 2.0.3 has started rolling out to HCP Vault Dedicated clusters on AWS and Azure.
</Release>

<Release source="hcp-changelog" date="June 30, 2026" published="2026-06-30T00:00:00.000Z" url="https://developer.hashicorp.com/hcp/docs/changelog#hcp-scim-provisioning" canonical="https://releases.sh/release/rel_DDA7H1WANQUZpRt-r-wSc" truncated="true">
### HCP SCIM provisioning

HCP now supports SCIM (System for Cross-domain Identity Management) provisioning for automated user and group lifecycle management. With SCIM enabled,...
</Release>

<Release source="terraform" version="v1.15.7" date="June 24, 2026" published="2026-06-24T16:47:12.000Z" url="https://github.com/hashicorp/terraform/releases/tag/v1.15.7" canonical="https://releases.sh/release/rel__Kbku3ft8F6RvkE5vC4Be" truncated="true">
Fixed submodule variable validation during init and added concurrency safety to configs.Parser and SourceBundleParser.
</Release>

<Release source="consul" version="v2.0.1" date="June 19, 2026" published="2026-06-19T07:23:26.000Z" url="https://github.com/hashicorp/consul/releases/tag/v2.0.1" canonical="https://releases.sh/release/rel_8pLk-oNkmldLsMeqoQNxQ" truncated="true">
Fixed a bug where renaming or rejoining a server could evict the live leader from the internal server lookup, causing Raft leader errors on follower RPCs. Inbound HTTP requests now have the x-forwarded-client-cert header stripped before forwarding to local services. Also includes Go and Envoy security upgrades, OIDC/JWT claim mapping support for auth method token names, and product telemetry export cadence preservation across restarts.
</Release>

<Release source="vault" version="v2.0.3" date="June 17, 2026" published="2026-06-17T20:23:38.000Z" url="https://github.com/hashicorp/vault/releases/tag/v2.0.3" canonical="https://releases.sh/release/rel_Kxk8EOqmbTPuQLpbNI5ws" truncated="true">
LIST requests with a trailing slash now correctly respect more-specific deny policies, fixing an ACL bypass where a request to `LIST kv/private/` could skip a `deny` on `kv/*`. Also introduces beta support for AI agents in Enterprise, including an agent registry and OAuth resource server capabilities. Plus a constant-time recovery token comparison and several security fixes across RADIUS, SPIFFE, and transform.
</Release>

## Fetching more

Append `.md` (markdown), `.json` (raw data), or `.atom` (feed) to any URL on this page.

- Per-source history: `https://releases.sh/hashicorp/{source-slug}`
- Atom feed: `https://releases.sh/hashicorp.atom`
- Individual release: `https://releases.sh/release/{release-id}`
