VYPR

consul-mcp-server

by Hashicorp

CVEs (2)

  • CVE-2026-16328HigJul 29, 2026
    risk 0.00cvss 8.6epss 0.00

    In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul…

  • CVE-2026-16326CriJul 29, 2026
    risk 0.00cvss 10.0epss 0.00

    In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in…