Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-19113

Consul: agent HTTP endpoints process unbounded request bodies before authorization

Technology

HashiCorp Consul

CVSS Score

5.3 / 10.0

Affected Versions

Consul and Consul Enterprise 1.3.0 through 2.0.2

Upstream Fix

2.0.3; Enterprise 1.21.17, 1.22.11

Published

August 7, 2026

OSSeva Coverage

Fixed upstream

Description

Several agent HTTP API endpoints processed request content before ACL authorization with no size limit, so an unauthenticated caller can make the agent consume memory before the request is rejected. Restricting the HTTP API to trusted clients, or requiring client certificates on the HTTPS listener, reduces exposure. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul and Consul Enterprise 1.3.0 through 2.0.2, you need this patch. Book a discovery call to get covered.