Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-11374

Consul: KV endpoint denial of service through incorrect Content-Length validation

Technology

HashiCorp Consul

CVSS Score

6.5 / 10.0

Affected Versions

Consul Community Edition up to 1.21.5; Consul Enterprise up to 1.21.5, 1.20.7, 1.19.9 and 1.18.11

Upstream Fix

Community 1.22.0; Enterprise 1.22.0, 1.21.6, 1.20.8, 1.18.12; no fix for 1.19

Published

October 28, 2025

OSSeva Coverage

Fixed upstream

Description

The key/value endpoint validates the Content-Length header incorrectly, allowing denial of service. HashiCorp's bulletin states that Enterprise 1.19 would get no fix because it was no longer an LTS version. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul Community Edition up to 1.21.5; Consul Enterprise up to 1.21.5, 1.20.7, 1.19.9 and 1.18.11, you need this patch. Book a discovery call to get covered.