Consul
HashiCorp- Product type
- Other
- Catalog vulnerabilities
- 48
Severity across 23 analyzed records
en
Verify to analyze this security profile
As of 09/13/2026, within CyStack's analyzed data, Consul has 12 security vulnerabilities published in the last 90 days. Of these, 3 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Consul and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-88021Consul vulnerable to an authorization bypass in the Connect service mesh | Exploitation statusNot known exploited | FixYes | Published09/10/2026 | SeverityHigh |
CVE-2026-87107Consul vulnerable to an authorization bypass in the catalog deregistration path | Exploitation statusNot known exploited | FixYes | Published09/10/2026 | SeverityMedium |
CVE-2026-87106Consul vulnerable to a denial of service in the native RPC listener | Exploitation statusNot known exploited | FixYes | Published09/10/2026 | SeverityMedium |
CVE-2026-87090Consul vulnerable to an authorization bypass in the catalog node-write path | Exploitation statusNot known exploited | FixYes | Published09/10/2026 | SeverityHigh |
CVE-2026-19113Unauthenticated denial of service via unbounded request body processing | Exploitation statusNot known exploited | FixYes | Published08/07/2026 | SeverityMedium |
CVE-2026-15972Unauthenticated denial of service via unbounded external gRPC connection acceptance | Exploitation statusNot known exploited | FixYes | Published08/07/2026 | SeverityHigh |
CVE-2026-15970L7 intention authorization bypass via custom public listener | Exploitation statusNot known exploited | FixYes | Published08/07/2026 | SeverityMedium |
CVE-2026-19017Consul vulnerable to partial arbitrary file read via Vault Connect CA provider | Exploitation statusNot known exploited | FixYes | Published08/07/2026 | SeverityMedium |
CVE-2026-19015Uncontrolled resource consumption in the Consul Connect CA roots endpoint | Exploitation statusNot known exploited | FixYes | Published08/07/2026 | SeverityMedium |
CVE-2026-19014Uncontrolled resource consumption in the Consul Connect authorization endpoint | Exploitation statusNot known exploited | FixYes | Published08/07/2026 | SeverityMedium |
CVE-2026-19012Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path | Exploitation statusNot known exploited | FixYes | Published08/07/2026 | SeverityMedium |
CVE-2026-19016Authorization bypass for session deletion in the transaction API | Exploitation statusNot known exploited | FixYes | Published08/07/2026 | SeverityMedium |
CVE-2026-2808Consul vulnerable to arbitrary file reads through the vault kubernetes authentication provider | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityMedium |
CVE-2025-11374Consul's KV endpoint is vulnerable to denial of service | Exploitation statusNot known exploited | FixYes | Published10/28/2025 | SeverityMedium |
CVE-2025-11375Consul's event endpoint is vulnerable to denial of service | Exploitation statusNot known exploited | FixYes | Published10/28/2025 | SeverityMedium |
CVE-2024-10086Consul Vulnerable To Reflected XSS On Content-Type Error Manipulation | Exploitation statusNot known exploited | FixYes | Published10/30/2024 | SeverityMedium |
CVE-2024-10006Consul L7 Intentions Vulnerable To Headers Bypass | Exploitation statusNot known exploited | FixYes | Published10/30/2024 | SeverityHigh |
CVE-2024-10005Consul L7 Intentions Vulnerable To URL Path Bypass | Exploitation statusNot known exploited | FixYes | Published10/30/2024 | SeverityHigh |
CVE-2023-5332Dependency on Vulnerable Third-Party Component in GitLab | Exploitation statusNot confirmed | FixYes | Published12/04/2023 | SeverityMedium |
CVE-2023-3518JWT Auth in L7 Intentions Allow For Mismatched Service Identity and JWT Providers for Access | Exploitation statusNot known exploited | FixYes | Published08/09/2023 | SeverityHigh |
CVE-2023-1297Consul Cluster Peering can Result in Denial of Service | Exploitation statusNot known exploited | FixYes | Published06/02/2023 | SeverityMedium |
CVE-2023-2816Consul Envoy Extension Downsteam Proxy Configuration By Upstream Service Owner | Exploitation statusNot known exploited | FixNot confirmed | Published06/02/2023 | SeverityHigh |
CVE-2023-0845Consul Server Panic when Ingress and API Gateways Configured with Peering | Exploitation statusNot known exploited | FixYes | Published03/09/2023 | SeverityMedium |
CVE-2022-3920Consul Peering Imported Nodes/Services Leak | Exploitation statusNot known exploited | FixYes | Published11/15/2022 | SeverityMedium |
CVE-2021-41803 | Exploitation statusNot known exploited | FixYes | Published09/23/2022 | SeverityHigh |
CVE-2022-40716 | Exploitation statusNot known exploited | FixYes | Published09/23/2022 | SeverityMedium |
CVE-2022-29153 | Exploitation statusNot confirmed | FixYes | Published04/19/2022 | SeverityUnknown |
CVE-2022-24687 | Exploitation statusNot confirmed | FixYes | Published02/24/2022 | SeverityUnknown |
CVE-2021-41805 | Exploitation statusNot confirmed | FixNot confirmed | Published12/12/2021 | SeverityUnknown |
CVE-2021-38698 | Exploitation statusNot confirmed | FixYes | Published09/07/2021 | SeverityUnknown |
CVE-2021-37219 | Exploitation statusNot confirmed | FixYes | Published09/07/2021 | SeverityUnknown |
CVE-2021-36213 | Exploitation statusNot confirmed | FixYes | Published07/17/2021 | SeverityUnknown |
CVE-2021-32574 | Exploitation statusNot confirmed | FixYes | Published07/17/2021 | SeverityUnknown |
CVE-2021-28156 | Exploitation statusNot confirmed | FixYes | Published04/20/2021 | SeverityUnknown |
CVE-2020-25864 | Exploitation statusNot confirmed | FixYes | Published04/20/2021 | SeverityUnknown |
CVE-2021-3121 | Exploitation statusNot confirmed | FixNot confirmed | Published01/11/2021 | SeverityUnknown |
CVE-2020-28053 | Exploitation statusNot confirmed | FixYes | Published11/23/2020 | SeverityUnknown |
CVE-2020-25201 | Exploitation statusNot confirmed | FixYes | Published11/04/2020 | SeverityUnknown |
CVE-2020-13170 | Exploitation statusNot confirmed | FixYes | Published06/11/2020 | SeverityUnknown |
CVE-2020-12797 | Exploitation statusNot confirmed | FixYes | Published06/11/2020 | SeverityUnknown |
CVE-2020-12758 | Exploitation statusNot confirmed | FixYes | Published06/11/2020 | SeverityUnknown |
CVE-2020-13250 | Exploitation statusNot confirmed | FixYes | Published06/11/2020 | SeverityUnknown |
CVE-2020-7219 | Exploitation statusNot confirmed | FixYes | Published01/31/2020 | SeverityUnknown |
CVE-2020-7955 | Exploitation statusNot confirmed | FixYes | Published01/31/2020 | SeverityUnknown |
CVE-2019-12291 | Exploitation statusNot confirmed | FixNot confirmed | Published06/06/2019 | SeverityUnknown |
CVE-2019-9764 | Exploitation statusNot confirmed | FixYes | Published03/26/2019 | SeverityUnknown |
CVE-2019-8336 | Exploitation statusNot confirmed | FixNot confirmed | Published03/05/2019 | SeverityUnknown |
CVE-2018-19653 | Exploitation statusNot confirmed | FixNot confirmed | Published12/09/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan