Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-14362

memberlist, embedded in Consul: crafted gossip push/pull message exhausts memory

Technology

HashiCorp Consul

CVSS Score

4.9 / 10.0

Affected Versions

HashiCorp memberlist up to 0.5.4, as embedded in Consul

Upstream Fix

memberlist 0.6.0; Consul 2.0.2

Published

July 8, 2026

OSSeva Coverage

Fixed upstream

Description

memberlist pre-allocated memory from the node count and user state length declared in a push/pull message header without checking them, so a small crafted message to the gossip port can make the receiving agent attempt a huge allocation and terminate. Without gossip encryption, the default, no authentication is needed; enabling gossip encryption limits exploitation to holders of the shared key. HashiCorp's bulletin names Consul 2.0.2 as the fixed release. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running HashiCorp memberlist up to 0.5.4, as embedded in Consul, you need this patch. Book a discovery call to get covered.