Denial of Service Vulnerability in Consul Community and Enterprise Edition by HashiCorp
CVE-2026-15972

7.5HIGH

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
7 August 2026

What is CVE-2026-15972?

Consul Community Edition and Consul Enterprise versions from 1.13.0 to 2.0.2 are exposed to a denial of service vulnerability due to unbounded connection acceptance on external gRPC listeners. Attackers can exploit this flaw to create numerous incomplete connections, thereby exhausting system resources such as agent file descriptors, goroutines, and memory. As a result, legitimate clients may face interruptions while connecting. It is crucial to update to Consul 2.0.3 or the patched Enterprise versions to mitigate this security risk.

Affected Version(s)

Consul 64 bit 1.13.0 < 2.0.3

Consul Enterprise 64 bit 1.13.0 < 2.0.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported by Erichen.
.