Back to blog

// OSSeva Blog

Security

HashiCorp Consul Vulnerabilities by Version: CVEs for Consul 1.x and 2.0, Community and Enterprise

Randall McClure10 min read

The short answer

HashiCorp supports three Consul lines: 2.0 until 30 April 2028, 1.21, the last long-term support release, until 30 April 2027, and 1.22 until 31 October 2026. 1.18 LTS ended on 30 April 2026 and 1.15 LTS on 30 April 2025. In 2026 HashiCorp has published 14 CVEs that affect Consul, 12 of them in August and September. All are fixed in Consul 2.0.4, released on 10 September 2026, and Consul Enterprise 1.21.18 and 1.22.12 carry every fix the bulletins list for those lines. Only one, CVE-2026-2808, is fixed in a Community Edition 1.x build, 1.22.5, because Community releases on 1.x stopped with 1.22.7 on 25 April 2026; since then only 2.0 gets Community builds.

So the question for a Consul cluster is not only which line it runs but which edition. An Enterprise customer on 1.21 or 1.22 has every fix. A Community user on any 1.x release, including 1.22.7, is missing at least 12 of the 2026 fixes, and the only Community release with them is 2.0.4. For the licence and support side of that decision, see Consul on an end-of-life version.

Consul release lines and their CVEs

Support dates are from HashiCorp's Consul Enterprise support page, and release dates from releases.hashicorp.com. The CVE column lists the CVEs from HashiCorp's security bulletins whose ranges include the line and that have no fix in its latest release.

LineUpstream statusLatest releaseCVEs with no fix on this lineUpstream fix on this line
2.0Supported to 30 April 2028; IBM Extended Support to 30 April 20292.0.4, Community and Enterprise, 10 September 2026None2.0.2, 2.0.3 and 2.0.4 carry the 2026 fixes
1.22Enterprise support to 31 October 2026Enterprise 1.22.12, 10 September 2026; Community 1.22.7, 25 April 2026Community 1.22.7: the eight August and four September CVEsEnterprise 1.22.11 and 1.22.12 only
1.21 LTSEnterprise LTS to 30 April 2027, the last LTSEnterprise 1.21.18, 10 September 2026; Community 1.21.5, 23 September 2025Community 1.21.5: CVE-2025-11374, CVE-2025-11375, CVE-2026-2808 and the August and September CVEsEnterprise 1.21.6, 1.21.11, 1.21.17 and 1.21.18 only
1.20Out of supportEnterprise 1.20.13, 26 November 2025; Community 1.20.6, 28 April 2025Most of the August and September CVEs; Community also CVE-2026-2808, CVE-2025-11374 and CVE-2025-11375Enterprise 1.20.8 for the 2025 CVEs; nothing for 2026
1.19Out of supportEnterprise 1.19.13, 23 September 2025; Community 1.19.2, 27 August 2024The 2025 and 2026 CVEs; Community also CVE-2024-10005, CVE-2024-10006 and CVE-2024-10086Enterprise 1.19.3 for the 2024 CVEs; HashiCorp declined to fix the 2025 CVEs on 1.19
1.18 LTSEnterprise LTS ended 30 April 2026Enterprise 1.18.22, 26 March 2026; Community 1.18.2, 17 May 2024Enterprise: the August and September CVEs whose ranges reach 1.18. Community: also every CVE from 2024 and 2025Enterprise 1.18.5, 1.18.12 and 1.18.21
1.17Out of support; first BSL releaseEnterprise 1.17.7, 27 August 2024; Community 1.17.3, 13 February 2024The 2024 and 2025 CVEs and most of those from 2026No upstream fix on this line
1.16Out of supportEnterprise 1.16.8, 17 May 2024; Community 1.16.6, 13 February 2024The 2024 and 2025 CVEs and most of those from 20261.16.1 for CVE-2023-3518; 1.16.3 updated components for CVE-2023-44487
1.15 LTSEnterprise LTS ended 30 April 2025Enterprise 1.15.19, 8 April 2025; Community 1.15.10, 13 February 2024Enterprise: the 2025 and 2026 CVEs. Community: also the 2024 CVEsEnterprise 1.15.15 for the 2024 CVEs; 1.15.3 for CVE-2023-2816 and CVE-2023-1297
1.14 and olderOut of support1.14.11, 31 October 2023Every CVE from 2024 on that reaches the lineNo upstream fix on these lines

Several of the 2026 CVEs start at old releases: CVE-2026-19015 at 1.2.0, CVE-2026-19113 at 1.3.0, CVE-2026-88021 at 1.9.0 and CVE-2026-15972 at 1.13.0, and CVE-2026-87090 lists every release up to 2.0.3. A cluster on any 1.x line outside Enterprise support is exposed to all of them. Consul is licensed under the Business Source License 1.1 from 1.17.0, and the licence file has named IBM as licensor since 18 March 2026. Later patch releases on the 1.15 and 1.16 branches, such as 1.15.11 and 1.16.5, also carry the BSL. For dates on every line, see the Consul end-of-life chart.

Notable Consul CVEs by release line

CVSS is NVD's own score where NVD has scored the record, otherwise HashiCorp's score as the CNA. NVD has not yet analysed the 2026 records. One CVE that reached Consul is in CISA's Known Exploited Vulnerabilities catalogue: CVE-2023-44487, the HTTP/2 Rapid Reset flaw, added on 10 October 2023, for which HashiCorp updated the affected components in 1.16.3, 1.15.7 and 1.14.11.

CVEIssueCVSSAffectedFixed in
CVE-2026-87090A token with node:write on any one node can delete another node's catalog registration and take over its node identity8.3 (HashiCorp)Up to 2.0.32.0.4; Enterprise 1.21.18, 1.22.12
CVE-2026-15972Unauthenticated callers can exhaust an agent by opening unbounded connections to the external gRPC listeners7.5 (HashiCorp)1.13.0 to 2.0.22.0.3; Enterprise 1.21.17, 1.22.11
CVE-2026-88021Envoy RBAC rules built from intentions do not escape some characters in service names, so a service can reach a destination it is not authorized for7.1 (HashiCorp)1.9.0 to 2.0.32.0.4; Enterprise 1.21.18, 1.22.12
CVE-2026-2808With the Vault CA provider on Kubernetes auth, a user with operator write can set token_path to any file on a server and send its contents to Vault6.8 (HashiCorp)Community up to 1.22.4; Enterprise up to 1.18.20, 1.21.10 and 1.22.41.22.5; Enterprise 1.18.21, 1.21.11, 1.22.5
CVE-2026-19017With the Vault CA provider on JWT or AppRole auth, the credential directory allowlist is too broad, so operator write can read files outside it6.8 (HashiCorp)1.18.21 to 2.0.22.0.3; Enterprise 1.21.17, 1.22.11
CVE-2026-87106The native RPC listener reads unbounded request headers before ACL checks, so any client that completes the mTLS handshake can exhaust server memory6.5 (HashiCorp)1.21.0 to 2.0.32.0.4; Enterprise 1.21.18, 1.22.12
CVE-2025-11374The KV endpoint validates the Content-Length header incorrectly, allowing denial of service6.5 (HashiCorp)Community up to 1.21.5; Enterprise up to 1.21.5, 1.20.7, 1.19.9 and 1.18.111.22.0; Enterprise 1.21.6, 1.20.8, 1.18.12
CVE-2025-11375The event endpoint sets no maximum Content-Length, allowing denial of service6.5 (HashiCorp)The same as CVE-2025-11374The same as CVE-2025-11374
CVE-2024-10086Server responses without an explicit Content-Type allow reflected cross-site scripting6.1 (NVD)Community 1.4.1 to 1.19.2; Enterprise up to 1.19.2, 1.18.4, 1.15.141.20.0; Enterprise 1.19.3, 1.18.5, 1.15.15
CVE-2024-10005URL paths in L7 intentions can be crafted to bypass path-based access rules5.8 (NVD)Community 1.9.0 to 1.20.0; Enterprise up to 1.20.0, 1.19.2, 1.18.4, 1.15.141.20.1; Enterprise 1.19.3, 1.18.5, 1.15.15
CVE-2024-10006Headers in L7 intentions can be crafted to bypass header-based access rules5.8 (NVD)The same as CVE-2024-10005The same as CVE-2024-10005
CVE-2026-19113Several agent HTTP endpoints read unbounded request bodies before ACL checks, an unauthenticated denial of service5.3 (HashiCorp)1.3.0 to 2.0.22.0.3; Enterprise 1.21.17, 1.22.11
CVE-2026-19015The Connect CA roots endpoint ignores http_config.use_cache, so remote callers can grow the agent cache without bound5.3 (HashiCorp)1.2.0 to 2.0.22.0.3; Enterprise 1.21.17, 1.22.11
CVE-2026-14362The memberlist gossip library pre-allocates memory from a push/pull header, so a crafted message to the gossip port can kill an agent4.9 (HashiCorp)memberlist before 0.6.0, as embedded in Consul2.0.2

The August batch also includes CVE-2026-19012, a crash in the Enterprise-to-Community downgrade path, CVE-2026-19014, an unbounded intention-match cache, CVE-2026-19016, session deletion through the transaction API without session:write, and CVE-2026-15970, an L7 intention bypass on custom public listeners. The September batch adds CVE-2026-87107, deletion of peer-imported catalog objects. All are fixed in 2.0.3 or 2.0.4 and the matching Enterprise releases.

Most of these come down to how much of Consul's network surface an attacker can reach. CVE-2026-15972, CVE-2026-19113 and CVE-2026-19015 need no ACL token at all, only access to the agent's external gRPC or HTTP listeners. CVE-2026-14362 needs no credentials either when gossip encryption is off, which is the default. CVE-2026-87106 needs only a certificate for the RPC port. The rest need a valid token, so a cluster with ACLs disabled, or one where most operators hold broad write rights, is exposed to all of them. CVE-2026-88021, CVE-2026-15970, CVE-2024-10005 and CVE-2024-10006 matter only where the service mesh and its intentions are in use.

HashiCorp also published three consul-template bulletins and one for the Consul MCP server in 2026. Those are separate binaries with their own versions and are not covered by the Consul releases above.

What each line gets

Consul 2.0

2.0.4 carries every fix above, for Community and Enterprise alike. From 2.0, Consul Enterprise follows IBM's Support Cycle-2 model in place of LTS releases, and 2.1.0 was at its first release candidate on 29 September 2026.

Consul 1.21 and 1.22

Enterprise 1.21.18 and 1.22.12 have every 2026 fix except, as far as HashiCorp's bulletin says, the memberlist fix, for which it names only 2.0.2. Community users on these lines have none of the August and September fixes, because the last Community builds were 1.21.5 and 1.22.7. Enterprise support for 1.22 ends on 31 October 2026 and HashiCorp's support page lists no IBM extended support for it, so 2.0 is the next step. See Consul 1.22 end of life.

Consul 1.18 to 1.20

1.18 was an LTS line, and Enterprise 1.18.22 from March 2026 carries the fixes up to CVE-2026-2808. Its support ended on 30 April 2026, before the August and September batches. 1.19 and 1.20 left support earlier, and the 2025 bulletins state that 1.19 would get no fix. Community builds on all three are years behind. See Consul 1.18 end of life.

Consul 1.17 and earlier

Nothing from October 2024 onward is fixed on these lines, apart from the Enterprise 1.15.15 fixes for the 2024 CVEs. 1.16.3 carries the updated HTTP/2 components for CVE-2023-44487 and the 1.16.1 fix for CVE-2023-3518, and 1.15.3 carries the fixes for CVE-2023-2816 and CVE-2023-1297. 1.16 and earlier also predate the move to the BSL at 1.17.0.

What to do on each line

  • 2.0. Take 2.0.4.
  • Enterprise 1.21 and 1.22. Take 1.21.18 or 1.22.12, and move off 1.22 before 31 October 2026.
  • Community 1.x. Move to 2.0.4, which is the only Community release with the 2026 fixes, or take patched builds. Until then, enable ACLs with a default deny policy, turn on gossip encryption, require TLS client certificates on the RPC and HTTPS listeners, and keep the HTTP API and external gRPC ports off untrusted networks. Setting http_config.use_cache to false does not mitigate CVE-2026-19014 or CVE-2026-19015.
  • Enterprise 1.18 and older. Use the LTS upgrade path to 1.21, then plan 2.0.

Consul is often the coordination store behind other systems, such as Patroni and Vitess, so an upgrade or replacement touches them too; see ZooKeeper, etcd, Consul and KRaft compared.

Where OSSeva fits

OSSeva ships patched, signed builds of MPL 2.0 Consul, 1.16.3 and earlier, rebuilt on a supported Go toolchain with patched dependencies and covering server and client agent binaries, delivered as binaries, Docker images and packages. OSSeva backports fixes of this class to the end-of-life release lines it patches. For clusters on the BSL lines, 1.17 and later, OSSeva does not redistribute modified BSL code; it plans and runs a supported upgrade to a maintained release, or a migration of coordination to etcd or Kubernetes. Patched builds are available now on the Patch, Assure and Operate tiers. Assure adds a version and licence inventory across every datacenter, an ACL, gossip encryption and TLS configuration audit and an upgrade or migration plan for 1.17 and later clusters, and Operate adds 24/7 Raft leadership, peer and autopilot health monitoring with a 15-minute P1 response and rolling upgrades with Raft quorum preserved. See Consul support.

Tags

HashiCorp ConsulCVEConsul 1.15Consul 2.0End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.