Authenticated Denial of Service in Consul by HashiCorp
CVE-2026-19012

5.3MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
7 August 2026

What is CVE-2026-19012?

The Authenticated Denial of Service vulnerability in the Consul platform allows an attacker, who possesses valid authorization, to exploit the downgrade path from the Enterprise to Community Edition. By submitting a specially crafted service-router configuration entry, an authorized user can trigger an unexpected termination of the Consul server, which can lead to service outages. This vulnerability has been addressed in subsequent updates, namely Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3, highlighting the importance of maintaining up-to-date software to mitigate such risks.

Affected Version(s)

Consul 64 bit 1.18.0 < 2.0.3

Consul Enterprise 64 bit 1.18.0 < 2.0.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported to HashiCorp by Erichen.
.