CVE-2026-19113
Consul: agent HTTP endpoints process unbounded request bodies before authorization
Technology
HashiCorp Consul
CVSS Score
5.3 / 10.0
Affected Versions
Consul and Consul Enterprise 1.3.0 through 2.0.2
Upstream Fix
2.0.3; Enterprise 1.21.17, 1.22.11
Published
August 7, 2026
OSSeva Coverage
Fixed upstream
Description
Several agent HTTP API endpoints processed request content before ACL authorization with no size limit, so an unauthenticated caller can make the agent consume memory before the request is rejected. Restricting the HTTP API to trusted clients, or requiring client certificates on the HTTPS listener, reduces exposure. The score is HashiCorp's as the CNA.
Is your HashiCorp Consul deployment affected?
If you're running Consul and Consul Enterprise 1.3.0 through 2.0.2, you need this patch. Book a discovery call to get covered.