// OSSeva Blog
SecurityHashiCorp Consul Vulnerabilities by Version: CVEs for Consul 1.x and 2.0, Community and Enterprise
The short answer
HashiCorp supports three Consul lines: 2.0 until 30 April 2028, 1.21, the last long-term support release, until 30 April 2027, and 1.22 until 31 October 2026. 1.18 LTS ended on 30 April 2026 and 1.15 LTS on 30 April 2025. In 2026 HashiCorp has published 14 CVEs that affect Consul, 12 of them in August and September. All are fixed in Consul 2.0.4, released on 10 September 2026, and Consul Enterprise 1.21.18 and 1.22.12 carry every fix the bulletins list for those lines. Only one, CVE-2026-2808, is fixed in a Community Edition 1.x build, 1.22.5, because Community releases on 1.x stopped with 1.22.7 on 25 April 2026; since then only 2.0 gets Community builds.
So the question for a Consul cluster is not only which line it runs but which edition. An Enterprise customer on 1.21 or 1.22 has every fix. A Community user on any 1.x release, including 1.22.7, is missing at least 12 of the 2026 fixes, and the only Community release with them is 2.0.4. For the licence and support side of that decision, see Consul on an end-of-life version.
Consul release lines and their CVEs
Support dates are from HashiCorp's Consul Enterprise support page, and release dates from releases.hashicorp.com. The CVE column lists the CVEs from HashiCorp's security bulletins whose ranges include the line and that have no fix in its latest release.
| Line | Upstream status | Latest release | CVEs with no fix on this line | Upstream fix on this line |
|---|---|---|---|---|
| 2.0 | Supported to 30 April 2028; IBM Extended Support to 30 April 2029 | 2.0.4, Community and Enterprise, 10 September 2026 | None | 2.0.2, 2.0.3 and 2.0.4 carry the 2026 fixes |
| 1.22 | Enterprise support to 31 October 2026 | Enterprise 1.22.12, 10 September 2026; Community 1.22.7, 25 April 2026 | Community 1.22.7: the eight August and four September CVEs | Enterprise 1.22.11 and 1.22.12 only |
| 1.21 LTS | Enterprise LTS to 30 April 2027, the last LTS | Enterprise 1.21.18, 10 September 2026; Community 1.21.5, 23 September 2025 | Community 1.21.5: CVE-2025-11374, CVE-2025-11375, CVE-2026-2808 and the August and September CVEs | Enterprise 1.21.6, 1.21.11, 1.21.17 and 1.21.18 only |
| 1.20 | Out of support | Enterprise 1.20.13, 26 November 2025; Community 1.20.6, 28 April 2025 | Most of the August and September CVEs; Community also CVE-2026-2808, CVE-2025-11374 and CVE-2025-11375 | Enterprise 1.20.8 for the 2025 CVEs; nothing for 2026 |
| 1.19 | Out of support | Enterprise 1.19.13, 23 September 2025; Community 1.19.2, 27 August 2024 | The 2025 and 2026 CVEs; Community also CVE-2024-10005, CVE-2024-10006 and CVE-2024-10086 | Enterprise 1.19.3 for the 2024 CVEs; HashiCorp declined to fix the 2025 CVEs on 1.19 |
| 1.18 LTS | Enterprise LTS ended 30 April 2026 | Enterprise 1.18.22, 26 March 2026; Community 1.18.2, 17 May 2024 | Enterprise: the August and September CVEs whose ranges reach 1.18. Community: also every CVE from 2024 and 2025 | Enterprise 1.18.5, 1.18.12 and 1.18.21 |
| 1.17 | Out of support; first BSL release | Enterprise 1.17.7, 27 August 2024; Community 1.17.3, 13 February 2024 | The 2024 and 2025 CVEs and most of those from 2026 | No upstream fix on this line |
| 1.16 | Out of support | Enterprise 1.16.8, 17 May 2024; Community 1.16.6, 13 February 2024 | The 2024 and 2025 CVEs and most of those from 2026 | 1.16.1 for CVE-2023-3518; 1.16.3 updated components for CVE-2023-44487 |
| 1.15 LTS | Enterprise LTS ended 30 April 2025 | Enterprise 1.15.19, 8 April 2025; Community 1.15.10, 13 February 2024 | Enterprise: the 2025 and 2026 CVEs. Community: also the 2024 CVEs | Enterprise 1.15.15 for the 2024 CVEs; 1.15.3 for CVE-2023-2816 and CVE-2023-1297 |
| 1.14 and older | Out of support | 1.14.11, 31 October 2023 | Every CVE from 2024 on that reaches the line | No upstream fix on these lines |
Several of the 2026 CVEs start at old releases: CVE-2026-19015 at 1.2.0, CVE-2026-19113 at 1.3.0, CVE-2026-88021 at 1.9.0 and CVE-2026-15972 at 1.13.0, and CVE-2026-87090 lists every release up to 2.0.3. A cluster on any 1.x line outside Enterprise support is exposed to all of them. Consul is licensed under the Business Source License 1.1 from 1.17.0, and the licence file has named IBM as licensor since 18 March 2026. Later patch releases on the 1.15 and 1.16 branches, such as 1.15.11 and 1.16.5, also carry the BSL. For dates on every line, see the Consul end-of-life chart.
Notable Consul CVEs by release line
CVSS is NVD's own score where NVD has scored the record, otherwise HashiCorp's score as the CNA. NVD has not yet analysed the 2026 records. One CVE that reached Consul is in CISA's Known Exploited Vulnerabilities catalogue: CVE-2023-44487, the HTTP/2 Rapid Reset flaw, added on 10 October 2023, for which HashiCorp updated the affected components in 1.16.3, 1.15.7 and 1.14.11.
| CVE | Issue | CVSS | Affected | Fixed in |
|---|---|---|---|---|
| CVE-2026-87090 | A token with node:write on any one node can delete another node's catalog registration and take over its node identity | 8.3 (HashiCorp) | Up to 2.0.3 | 2.0.4; Enterprise 1.21.18, 1.22.12 |
| CVE-2026-15972 | Unauthenticated callers can exhaust an agent by opening unbounded connections to the external gRPC listeners | 7.5 (HashiCorp) | 1.13.0 to 2.0.2 | 2.0.3; Enterprise 1.21.17, 1.22.11 |
| CVE-2026-88021 | Envoy RBAC rules built from intentions do not escape some characters in service names, so a service can reach a destination it is not authorized for | 7.1 (HashiCorp) | 1.9.0 to 2.0.3 | 2.0.4; Enterprise 1.21.18, 1.22.12 |
| CVE-2026-2808 | With the Vault CA provider on Kubernetes auth, a user with operator write can set token_path to any file on a server and send its contents to Vault | 6.8 (HashiCorp) | Community up to 1.22.4; Enterprise up to 1.18.20, 1.21.10 and 1.22.4 | 1.22.5; Enterprise 1.18.21, 1.21.11, 1.22.5 |
| CVE-2026-19017 | With the Vault CA provider on JWT or AppRole auth, the credential directory allowlist is too broad, so operator write can read files outside it | 6.8 (HashiCorp) | 1.18.21 to 2.0.2 | 2.0.3; Enterprise 1.21.17, 1.22.11 |
| CVE-2026-87106 | The native RPC listener reads unbounded request headers before ACL checks, so any client that completes the mTLS handshake can exhaust server memory | 6.5 (HashiCorp) | 1.21.0 to 2.0.3 | 2.0.4; Enterprise 1.21.18, 1.22.12 |
| CVE-2025-11374 | The KV endpoint validates the Content-Length header incorrectly, allowing denial of service | 6.5 (HashiCorp) | Community up to 1.21.5; Enterprise up to 1.21.5, 1.20.7, 1.19.9 and 1.18.11 | 1.22.0; Enterprise 1.21.6, 1.20.8, 1.18.12 |
| CVE-2025-11375 | The event endpoint sets no maximum Content-Length, allowing denial of service | 6.5 (HashiCorp) | The same as CVE-2025-11374 | The same as CVE-2025-11374 |
| CVE-2024-10086 | Server responses without an explicit Content-Type allow reflected cross-site scripting | 6.1 (NVD) | Community 1.4.1 to 1.19.2; Enterprise up to 1.19.2, 1.18.4, 1.15.14 | 1.20.0; Enterprise 1.19.3, 1.18.5, 1.15.15 |
| CVE-2024-10005 | URL paths in L7 intentions can be crafted to bypass path-based access rules | 5.8 (NVD) | Community 1.9.0 to 1.20.0; Enterprise up to 1.20.0, 1.19.2, 1.18.4, 1.15.14 | 1.20.1; Enterprise 1.19.3, 1.18.5, 1.15.15 |
| CVE-2024-10006 | Headers in L7 intentions can be crafted to bypass header-based access rules | 5.8 (NVD) | The same as CVE-2024-10005 | The same as CVE-2024-10005 |
| CVE-2026-19113 | Several agent HTTP endpoints read unbounded request bodies before ACL checks, an unauthenticated denial of service | 5.3 (HashiCorp) | 1.3.0 to 2.0.2 | 2.0.3; Enterprise 1.21.17, 1.22.11 |
| CVE-2026-19015 | The Connect CA roots endpoint ignores http_config.use_cache, so remote callers can grow the agent cache without bound | 5.3 (HashiCorp) | 1.2.0 to 2.0.2 | 2.0.3; Enterprise 1.21.17, 1.22.11 |
| CVE-2026-14362 | The memberlist gossip library pre-allocates memory from a push/pull header, so a crafted message to the gossip port can kill an agent | 4.9 (HashiCorp) | memberlist before 0.6.0, as embedded in Consul | 2.0.2 |
The August batch also includes CVE-2026-19012, a crash in the Enterprise-to-Community downgrade path, CVE-2026-19014, an unbounded intention-match cache, CVE-2026-19016, session deletion through the transaction API without session:write, and CVE-2026-15970, an L7 intention bypass on custom public listeners. The September batch adds CVE-2026-87107, deletion of peer-imported catalog objects. All are fixed in 2.0.3 or 2.0.4 and the matching Enterprise releases.
Most of these come down to how much of Consul's network surface an attacker can reach. CVE-2026-15972, CVE-2026-19113 and CVE-2026-19015 need no ACL token at all, only access to the agent's external gRPC or HTTP listeners. CVE-2026-14362 needs no credentials either when gossip encryption is off, which is the default. CVE-2026-87106 needs only a certificate for the RPC port. The rest need a valid token, so a cluster with ACLs disabled, or one where most operators hold broad write rights, is exposed to all of them. CVE-2026-88021, CVE-2026-15970, CVE-2024-10005 and CVE-2024-10006 matter only where the service mesh and its intentions are in use.
HashiCorp also published three consul-template bulletins and one for the Consul MCP server in 2026. Those are separate binaries with their own versions and are not covered by the Consul releases above.
What each line gets
Consul 2.0
2.0.4 carries every fix above, for Community and Enterprise alike. From 2.0, Consul Enterprise follows IBM's Support Cycle-2 model in place of LTS releases, and 2.1.0 was at its first release candidate on 29 September 2026.
Consul 1.21 and 1.22
Enterprise 1.21.18 and 1.22.12 have every 2026 fix except, as far as HashiCorp's bulletin says, the memberlist fix, for which it names only 2.0.2. Community users on these lines have none of the August and September fixes, because the last Community builds were 1.21.5 and 1.22.7. Enterprise support for 1.22 ends on 31 October 2026 and HashiCorp's support page lists no IBM extended support for it, so 2.0 is the next step. See Consul 1.22 end of life.
Consul 1.18 to 1.20
1.18 was an LTS line, and Enterprise 1.18.22 from March 2026 carries the fixes up to CVE-2026-2808. Its support ended on 30 April 2026, before the August and September batches. 1.19 and 1.20 left support earlier, and the 2025 bulletins state that 1.19 would get no fix. Community builds on all three are years behind. See Consul 1.18 end of life.
Consul 1.17 and earlier
Nothing from October 2024 onward is fixed on these lines, apart from the Enterprise 1.15.15 fixes for the 2024 CVEs. 1.16.3 carries the updated HTTP/2 components for CVE-2023-44487 and the 1.16.1 fix for CVE-2023-3518, and 1.15.3 carries the fixes for CVE-2023-2816 and CVE-2023-1297. 1.16 and earlier also predate the move to the BSL at 1.17.0.
What to do on each line
- 2.0. Take 2.0.4.
- Enterprise 1.21 and 1.22. Take 1.21.18 or 1.22.12, and move off 1.22 before 31 October 2026.
- Community 1.x. Move to 2.0.4, which is the only Community release with the 2026 fixes, or take patched builds. Until then, enable ACLs with a default deny policy, turn on gossip encryption, require TLS client certificates on the RPC and HTTPS listeners, and keep the HTTP API and external gRPC ports off untrusted networks. Setting http_config.use_cache to false does not mitigate CVE-2026-19014 or CVE-2026-19015.
- Enterprise 1.18 and older. Use the LTS upgrade path to 1.21, then plan 2.0.
Consul is often the coordination store behind other systems, such as Patroni and Vitess, so an upgrade or replacement touches them too; see ZooKeeper, etcd, Consul and KRaft compared.
Where OSSeva fits
OSSeva ships patched, signed builds of MPL 2.0 Consul, 1.16.3 and earlier, rebuilt on a supported Go toolchain with patched dependencies and covering server and client agent binaries, delivered as binaries, Docker images and packages. OSSeva backports fixes of this class to the end-of-life release lines it patches. For clusters on the BSL lines, 1.17 and later, OSSeva does not redistribute modified BSL code; it plans and runs a supported upgrade to a maintained release, or a migration of coordination to etcd or Kubernetes. Patched builds are available now on the Patch, Assure and Operate tiers. Assure adds a version and licence inventory across every datacenter, an ACL, gossip encryption and TLS configuration audit and an upgrade or migration plan for 1.17 and later clusters, and Operate adds 24/7 Raft leadership, peer and autopilot health monitoring with a 15-minute P1 response and rolling upgrades with Raft quorum preserved. See Consul support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.