Denial of Service Vulnerability in Consul and Consul Enterprise
CVE-2025-11374
6.5MEDIUM
What is CVE-2025-11374?
Consul and Consul Enterprise are impacted by a vulnerability affecting the key/value endpoint that allows for denial of service attacks. This flaw arises from improper validation of the Content Length header, which can be exploited to disrupt services and degrade system performance. Users are advised to upgrade to the fixed versions to mitigate potential risks.
Affected Version(s)
Consul 64 bit 0 < 1.22.0
Consul Enterprise 64 bit 1.22.0 < 0