VYPR

Bitnami package

consul

pkg:bitnami/consul

Vulnerabilities (52)

  • CVE-2026-88021HigSep 10, 2026
    affected >= 1.9.0, < 2.0.4fixed 2.0.4

    Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain

  • CVE-2026-87993HigSep 10, 2026
    affected >= 0.27.2, < 0.43.0fixed 0.43.0

    The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is f

  • CVE-2026-87107MedSep 10, 2026
    affected >= 1.21.0, < 2.0.4fixed 2.0.4

    Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove servic

  • CVE-2026-87106MedSep 10, 2026
    affected >= 1.21.0, < 2.0.4fixed 2.0.4

    Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue w

  • CVE-2026-87090HigSep 10, 2026
    affected >= 0.1.0, < 2.0.4fixed 2.0.4

    Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on

  • CVE-2026-8715CriAug 13, 2026
    affected >= 1.3.0, < 1.5.0fixed 1.5.0

    Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and tra

  • CVE-2026-19113MedAug 7, 2026
    affected >= 1.3.0, < 2.0.3fixed 2.0.3

    Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was rejected. This vulnerability,

  • CVE-2026-19017MedAug 7, 2026
    affected >= 1.18.21, < 2.0.3fixed 2.0.3

    Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul t

  • CVE-2026-19016MedAug 7, 2026
    affected >= 1.19.1, < 2.0.3fixed 2.0.3

    Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete a

  • CVE-2026-19015MedAug 7, 2026
    affected >= 1.2.0, < 2.0.3fixed 2.0.3

    Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache

  • CVE-2026-19014MedAug 7, 2026
    affected >= 1.17.0, < 2.0.3fixed 2.0.3

    Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-d

  • CVE-2026-19012MedAug 7, 2026
    affected >= 1.18.0, < 2.0.3fixed 2.0.3

    Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul server. A caller with config-entry write permissi

  • CVE-2026-15972HigAug 7, 2026
    affected >= 1.13.0, < 2.0.3fixed 2.0.3

    Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by openi

  • CVE-2026-15970MedAug 7, 2026
    affected >= 1.20.1, < 2.0.3fixed 2.0.3

    Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny i

  • CVE-2026-16328HigJul 29, 2026
    affected >= 0.1.0, < 0.1.4fixed 0.1.4

    In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul AP

  • CVE-2026-16326CriJul 29, 2026
    affected >= 0.1.0, < 0.1.4fixed 0.1.4

    In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-se

  • CVE-2026-16498CriJul 28, 2026
    affected >= 0.3.0, < 1.1.0fixed 1.1.0

    The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2

  • CVE-2026-16496HigJul 28, 2026
    affected >= 0.3.0, < 1.1.0fixed 1.1.0

    The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vu

  • CVE-2026-14869HigJul 28, 2026
    affected >= 0.3.0, < 1.1.0fixed 1.1.0

    The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an atta

  • CVE-2026-5061MedMay 12, 2026
    affected >= 0.1.0, < 0.42.0fixed 0.42.0

    The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.

Page 1 of 3