CVE-2026-15972
Consul: unbounded connections to the external gRPC listeners allow unauthenticated denial of service
Technology
HashiCorp Consul
CVSS Score
7.5 / 10.0
Affected Versions
Consul and Consul Enterprise 1.13.0 through 2.0.2
Upstream Fix
2.0.3; Enterprise 1.21.17, 1.22.11
Published
August 7, 2026
OSSeva Coverage
Fixed upstream
Description
The external gRPC and gRPC-TLS listeners applied no per-source connection limit or short establishment timeout, unlike Consul's other listeners. A remote caller with no token can hold many incomplete connections and exhaust the agent's file descriptors, goroutines and memory. Deployments that do not enable the external gRPC listeners are not affected. The score is HashiCorp's as the CNA.
Is your HashiCorp Consul deployment affected?
If you're running Consul and Consul Enterprise 1.13.0 through 2.0.2, you need this patch. Book a discovery call to get covered.