Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESHASHICORPVERIFIED

PUBLISHER UPDATE · NOMAD-1.11.8

NOMAD-1.11.8 release notes and known issues

v1.11.8 (Enterprise)

Scope: HashiCorp Nomad. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

SECURITY: docker: Enforce allowed_modes or allow_privileged requirement to set host namespace modes in task. This is CVE-2026-14891 . [ GH-28190 ] docker: Fixed a bug where docker tasks could use a symlink to bypass the plugin configuration for volumes.enabled=false. This is CVE-2026-14896 . [ GH-28177 ] dynamic host volumes: Fixed a bug where users with host-volume-delete in one namespace could delete claims from another namespace [ GH-28205 ] IMPROVEMENTS: consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [ GH-28106 ] driver: Added optional Init function for task driver plugins [ GH-28104 ] driver: Added optional Shutdown function for task driver plugins [ GH-28102 ] BUG FIXES: api: allow using WI tokens on plan endpoint [ GH-28139 ] cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [ GH-28138 ] dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [ GH-28198 ] metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [ GH-28170 ] scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [ GH-28097 ] scheduler: Fixed a bug where setting sticky on a static host volume could fail the evaluation instead of being rejected during feasibility checking [ GH-28097 ] scheduler: keep draining batch alloc counted when node is re-enabled [ GH-28018 ] task runner: Improve the memory management for secrets [ GH-28140 ] ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the /v1/jobs/statuses endpoint [ GH-28132 ] ui: fixes an issue where streaming task logs would error [ GH-28137 ]

Improvements and security content

  • SECURITY: docker: Enforce allowed_modes or allow_privileged requirement to set host namespace modes in task. This is CVE-2026-14891 . [ GH-28190 ] docker: Fixed a bug where docker tasks could use a symlink to bypass the plugin configuration for volumes.enabled=false. This is CVE-2026-14896 . [ GH-28177 ] dynamic host volumes: Fixed a bug where users with host-volume-delete in one namespace could delete claims from another namespace [ GH-28205 ] IMPROVEMENTS: consul: Allow service, template, and connect blocks to fallback to the Nomad client agent's Consul token if workload identity is unavailable [ GH-28106 ] driver: Added optional Init function for task driver plugins [ GH-28104 ] driver: Added optional Shutdown function for task driver plugins [ GH-28102 ] BUG FIXES: api: allow using WI tokens on plan endpoint [ GH-28139 ] cli: Fixed a bug where complex HCL variables passed via -var flag could not be edited in the web UI [ GH-28138 ] dynamic host volumes: Fixed a bug where allocations claiming host volumes with the per_alloc flag would not prevent the volume from being deleted [ GH-28198 ] metrics: expired metrics are now periodically cleared from the Prometheus sink even if no collection occurs [ GH-28170 ] scheduler: Fixed a bug where a node could be marked feasible for a task group requesting multiple host volumes when a satisfied sticky volume request short-circuited the checks for the remaining requests [ GH-28097 ] scheduler: Fixed a bug where setting sticky on a static host volume could fail the evaluation instead of being rejected during feasibility checking [ GH-28097 ] scheduler: keep draining batch alloc counted when node is re-enabled [ GH-28018 ] task runner: Improve the memory management for secrets [ GH-28140 ] ui: Fixed a bug where jobs that share a ModifyIndex (for example, several jobs rescheduled in a single Raft transaction after a node failure) were omitted from the jobs page and the /v1/jobs/statuses endpoint [ GH-28132 ] ui: fixes an issue where streaming task logs would error [ GH-28137 ]

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • HashiCorp Nomad

Affected versions

  • 1.11.8

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

HASHICORPVERIFIED

v1.11.8 (Enterprise)

Checked 4 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source