Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-11375

Consul: event endpoint denial of service through unbounded Content-Length

Technology

HashiCorp Consul

CVSS Score

6.5 / 10.0

Affected Versions

Consul Community Edition up to 1.21.5; Consul Enterprise up to 1.21.5, 1.20.7, 1.19.9 and 1.18.11

Upstream Fix

Community 1.22.0; Enterprise 1.22.0, 1.21.6, 1.20.8, 1.18.12; no fix for 1.19

Published

October 28, 2025

OSSeva Coverage

Fixed upstream

Description

The event endpoint sets no maximum on the Content-Length header, allowing denial of service. HashiCorp's bulletin states that Enterprise 1.19 would get no fix. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul Community Edition up to 1.21.5; Consul Enterprise up to 1.21.5, 1.20.7, 1.19.9 and 1.18.11, you need this patch. Book a discovery call to get covered.