Uncontrolled Resource Consumption in Consul Community Edition and Enterprise by HashiCorp
CVE-2026-19015

5.3MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
7 August 2026

What is CVE-2026-19015?

An uncontrolled resource consumption vulnerability exists in the Connect CA roots endpoint of Consul Community Edition and Consul Enterprise, versions 1.2.0 through 2.0.2. This flaw allows a remote caller to escalate the cache size of the agent's Connect CA roots indefinitely, potentially breaching the operator’s cache-disable settings. Such behavior can lead to performance degradation and resource exhaustion, posing operational risks. The vulnerability can be mitigated by updating to Consul 2.0.3 or later versions.

Affected Version(s)

Consul 64 bit 1.2.0 < 2.0.3

Consul Enterprise 64 bit 1.2.0 < 2.0.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported to HashiCorp by Erichen.
.