<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE on Cloudkaramchari</title><link>https://www.cloudkaramchari.com/tags/cve/</link><description>Recent content in CVE on Cloudkaramchari</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>cloudkaramchari</copyright><lastBuildDate>Sat, 08 Aug 2026 20:00:00 +0530</lastBuildDate><atom:link href="https://www.cloudkaramchari.com/tags/cve/index.xml" rel="self" type="application/rss+xml"/><item><title>Terraform MCP Server Had a CVSS 10.0 Bug: Patch to 1.2.0 Now</title><link>https://www.cloudkaramchari.com/blog/terraform-mcp-server-cvss-10-vulnerabilities-patch-now/</link><pubDate>Sat, 08 Aug 2026 20:00:00 +0530</pubDate><guid>https://www.cloudkaramchari.com/blog/terraform-mcp-server-cvss-10-vulnerabilities-patch-now/</guid><description>
&lt;h1 id="terraform-mcp-server-had-a-cvss-100-bug-patch-to-120-now">Terraform MCP Server Had a CVSS 10.0 Bug: Patch to 1.2.0 Now&lt;/h1>
&lt;p>If you've stood up HashiCorp's &lt;code>terraform-mcp-server&lt;/code> so an AI agent can query the Terraform Registry or talk to your workspaces, go check its version right now. HashiCorp Security Advisory HCSEC-2026-23, published July 28, 2026, covers three vulnerabilities in the server's streamable-HTTP transport — the worst of them, CVE-2026-16498, is a maximum-severity 10.0 on the CVSS scale. It lets one tenant's requests get serviced with a completely different tenant's Terraform credentials, with no authentication required from the attacker.&lt;/p></description></item></channel></rss>