Denial of Service Vulnerability in Consul and Consul Enterprise by HashiCorp
CVE-2025-11375
6.5MEDIUM
What is CVE-2025-11375?
The event endpoint in Consul and Consul Enterprise by HashiCorp is susceptible to a denial of service attack due to an unregulated maximum value for the Content Length header. This flaw could allow malicious actors to exploit the endpoint, potentially overwhelming it and causing service interruptions. Affected versions include Consul Community Edition 1.22.0 and multiple versions of Consul Enterprise, with fixes implemented in several releases.
Affected Version(s)
Consul 64 bit 0 < 1.22.0
Consul Enterprise 64 bit 1.22.0 < 0