Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-19015
Consul: Connect CA roots endpoint ignores the cache-disable setting
Technology
HashiCorp Consul
CVSS Score
5.3 / 10.0
Affected Versions
Consul and Consul Enterprise 1.2.0 through 2.0.2
Upstream Fix
2.0.3; Enterprise 1.21.17, 1.22.11
Published
August 7, 2026
OSSeva Coverage
Fixed upstream
Description
The GET /v1/agent/connect/ca/roots endpoint used the agent cache regardless of http_config.use_cache, so a remote caller without an ACL token can grow the cache without bound and degrade the agent. Setting http_config.use_cache to false does not mitigate it on affected versions. The score is HashiCorp's as the CNA.
Is your HashiCorp Consul deployment affected?
If you're running Consul and Consul Enterprise 1.2.0 through 2.0.2, you need this patch. Book a discovery call to get covered.