Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-15972

Consul: unbounded connections to the external gRPC listeners allow unauthenticated denial of service

Technology

HashiCorp Consul

CVSS Score

7.5 / 10.0

Affected Versions

Consul and Consul Enterprise 1.13.0 through 2.0.2

Upstream Fix

2.0.3; Enterprise 1.21.17, 1.22.11

Published

August 7, 2026

OSSeva Coverage

Fixed upstream

Description

The external gRPC and gRPC-TLS listeners applied no per-source connection limit or short establishment timeout, unlike Consul's other listeners. A remote caller with no token can hold many incomplete connections and exhaust the agent's file descriptors, goroutines and memory. Deployments that do not enable the external gRPC listeners are not affected. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul and Consul Enterprise 1.13.0 through 2.0.2, you need this patch. Book a discovery call to get covered.