CyberRota Analysis
AI-GeneratedHashiCorp memberlist versions prior to 0.6.0 are susceptible to a denial-of-service vulnerability that can be exploited by an attacker with network access to the gossip port, potentially leading to memory exhaustion and process termination on affected nodes. Organizations using this software should prioritize upgrading to version 0.6.0 or later to mitigate the risk of service disruption.
Original NVD Description
HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.