Uncontrolled Resource Consumption in Consul Community and Enterprise Products
CVE-2026-19014
4.3MEDIUM
What is CVE-2026-19014?
A resource consumption issue exists in the Connect authorization endpoint of Consul Community Edition and Enterprise versions ranging from 1.17.0 to 2.0.2. This vulnerability permits a malefactor to exploit the intention-match cache, leading to excessive resource usage that can compromise the intended cache-disable configurations set by operators. The issue has been resolved in Consul versions 2.0.3, 1.21.17, and 1.22.11.
Affected Version(s)
Consul 64 bit 1.17.0 < 2.0.3
Consul Enterprise 64 bit 1.17.0 < 2.0.3