VYPR

Consul

by Hashicorp

Source repositories

CVEs (49)

  • CVE-2026-19014MedAug 7, 2026
    risk 0.28cvss 4.3epss 0.00

    Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's…

  • CVE-2022-3920MedNov 16, 2022
    risk 0.28cvss 5.3epss 0.01

    HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.

  • CVE-2020-12797MedJun 11, 2020
    risk 0.28cvss 5.3epss 0.02

    HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

  • CVE-2026-19113MedAug 7, 2026
    risk 0.27cvss 5.3epss 0.00

    Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was rejected. This vulnerability,…

  • CVE-2026-15970MedAug 7, 2026
    risk 0.27cvss 4.2epss 0.00

    Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny…

  • CVE-2026-19016MedAug 7, 2026
    risk 0.20cvss 4.2epss 0.00

    Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete…

  • CVE-2021-41803HigSep 23, 2022
    risk 0.00cvss 7.1epss 0.01

    HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."

  • CVE-2021-38698MedSep 7, 2021
    risk 0.00cvss 6.5epss 0.01

    HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.

  • CVE-2020-25201HigNov 4, 2020
    risk 0.00cvss 7.5epss 0.03

    HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.

Page 3 of 3