CVE-2021-36213
Description
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
HashiCorp Consul 1.9.0-1.10.0 default deny policy with a single L7 deny intention fails open, allowing L4 traffic.
Vulnerability
HashiCorp Consul and Consul Enterprise versions 1.9.0 through 1.10.0 are affected by a vulnerability where a default deny policy combined with a single L7 application-aware intention that also has a deny action causes the intention to incorrectly fail open, allowing L4 traffic that should be denied. This issue was identified internally and affects Consul's service mesh intentions logic. [1][3]
Exploitation
An attacker with network access to a Consul service mesh configured with a default deny policy and a single L7 deny intention can exploit this vulnerability by sending L4 traffic to services that are intended to be denied. The attacker does not require authentication, as the configuration effectively nullifies the intended access control. [3]
Impact
Successful exploitation allows an attacker to bypass the intended deny policy, permitting L4 traffic to services that should be blocked. This can lead to unauthorized access to services within the mesh, potentially exposing sensitive data or services. [3]
Mitigation
The vulnerability is fixed in Consul versions 1.9.8 and 1.10.1. Users running affected versions should upgrade immediately. If upgrade is not possible, remove any redundant L7 deny intentions that duplicate the default deny policy as a workaround. [3][4]
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/hashicorp/consulGo | < 1.10.1 | 1.10.1 |
Affected products
27- HashiCorp/Consuldescription
- osv-coords26 versionspkg:apk/chainguard/consul-1.15pkg:apk/chainguard/consul-1.15-oci-entrypointpkg:apk/chainguard/consul-1.15-oci-entrypoint-compatpkg:apk/chainguard/consul-1.16pkg:apk/chainguard/consul-1.16-oci-entrypointpkg:apk/chainguard/consul-1.16-oci-entrypoint-compatpkg:apk/chainguard/consul-1.17pkg:apk/chainguard/consul-1.17-fipspkg:apk/chainguard/consul-1.17-fips-oci-entrypointpkg:apk/chainguard/consul-1.17-fips-oci-entrypoint-compatpkg:apk/chainguard/consul-1.17-oci-entrypointpkg:apk/chainguard/consul-1.17-oci-entrypoint-compatpkg:apk/chainguard/k3dpkg:apk/chainguard/k3d-proxypkg:apk/chainguard/k3d-toolspkg:apk/wolfi/consul-1.15pkg:apk/wolfi/consul-1.15-oci-entrypointpkg:apk/wolfi/consul-1.15-oci-entrypoint-compatpkg:apk/wolfi/consul-1.16pkg:apk/wolfi/consul-1.16-oci-entrypointpkg:apk/wolfi/consul-1.16-oci-entrypoint-compatpkg:apk/wolfi/k3dpkg:apk/wolfi/k3d-proxypkg:apk/wolfi/k3d-toolspkg:bitnami/consulpkg:golang/github.com/hashicorp/consul
< 1.15.11-r5+ 25 more
- (no CPE)range: < 1.15.11-r5
- (no CPE)range: < 1.15.11-r5
- (no CPE)range: < 1.15.11-r5
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 1.15.11-r5
- (no CPE)range: < 1.15.11-r5
- (no CPE)range: < 1.15.11-r5
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: < 5.6.0-r11
- (no CPE)range: >= 1.9.0, < 1.9.8
- (no CPE)range: < 1.10.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/advisories/GHSA-8h2g-r292-j8xhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-36213ghsaADVISORY
- security.gentoo.org/glsa/202208-09ghsavendor-advisoryx_refsource_GENTOOWEB
- discuss.hashicorp.com/t/hcsec-2021-16-consul-s-application-aware-intentions-deny-action-fails-open-when-combined-with-default-deny-policy/26855ghsax_refsource_CONFIRMWEB
- github.com/hashicorp/consul/releases/tag/v1.10.1ghsax_refsource_CONFIRMWEB
- www.hashicorp.com/blog/category/consulghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.