VYPR

consul-mcp-server

by Hashicorp

CVEs (2)

  • CVE-2026-16326Jul 29, 2026
    risk 0.00cvss epss 0.00

    In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in…

  • CVE-2026-16328Jul 29, 2026
    risk 0.00cvss epss 0.00

    In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul…