Denial of Service Vulnerability in Consul by HashiCorp
CVE-2026-19113

5.3MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
7 August 2026

What is CVE-2026-19113?

Consul by HashiCorp, both Community and Enterprise Editions from versions 1.3.0 to 2.0.2, presents a vulnerability that allows an unauthenticated remote attacker to exploit several agent HTTP API endpoints. This exploit can lead to excessive memory consumption for the Consul agent until requests are ultimately rejected, potentially affecting system performance and availability. Resolution for this vulnerability is implemented in Consul version 2.0.3 and the Enterprise versions 1.21.17, 1.22.11, and 2.0.3.

Affected Version(s)

Consul 64 bit 1.3.0 < 2.0.3

Consul Enterprise 64 bit 1.3.0 < 2.0.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported by Yazdan Soltani.
.