Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-19015

Consul: Connect CA roots endpoint ignores the cache-disable setting

Technology

HashiCorp Consul

CVSS Score

5.3 / 10.0

Affected Versions

Consul and Consul Enterprise 1.2.0 through 2.0.2

Upstream Fix

2.0.3; Enterprise 1.21.17, 1.22.11

Published

August 7, 2026

OSSeva Coverage

Fixed upstream

Description

The GET /v1/agent/connect/ca/roots endpoint used the agent cache regardless of http_config.use_cache, so a remote caller without an ACL token can grow the cache without bound and degrade the agent. Setting http_config.use_cache to false does not mitigate it on affected versions. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul and Consul Enterprise 1.2.0 through 2.0.2, you need this patch. Book a discovery call to get covered.