CVE-2026-14362
memberlist, embedded in Consul: crafted gossip push/pull message exhausts memory
Technology
HashiCorp Consul
CVSS Score
4.9 / 10.0
Affected Versions
HashiCorp memberlist up to 0.5.4, as embedded in Consul
Upstream Fix
memberlist 0.6.0; Consul 2.0.2
Published
July 8, 2026
OSSeva Coverage
Fixed upstream
Description
memberlist pre-allocated memory from the node count and user state length declared in a push/pull message header without checking them, so a small crafted message to the gossip port can make the receiving agent attempt a huge allocation and terminate. Without gossip encryption, the default, no authentication is needed; enabling gossip encryption limits exploitation to holders of the shared key. HashiCorp's bulletin names Consul 2.0.2 as the fixed release. The score is HashiCorp's as the CNA.
Is your HashiCorp Consul deployment affected?
If you're running HashiCorp memberlist up to 0.5.4, as embedded in Consul, you need this patch. Book a discovery call to get covered.