Medium severity5.3NVD Advisory· Published Aug 7, 2026· Updated Aug 28, 2026
CVE-2026-19113
CVE-2026-19113
Description
Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was rejected. This vulnerability, CVE-2026-19113, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versions
>= 1.3.0, < 2.0.3+ 1 more
- (no CPE)range: >= 1.3.0, < 2.0.3
- (no CPE)range: < 2.0.3-r0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.