Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-87106

Consul: native RPC listener memory exhaustion before ACL checks

Technology

HashiCorp Consul

CVSS Score

6.5 / 10.0

Affected Versions

Consul and Consul Enterprise 1.21.0 through 2.0.3

Upstream Fix

2.0.4; Enterprise 1.21.18, 1.22.12

Published

September 10, 2026

OSSeva Coverage

Fixed upstream

Description

The native RPC request decoder, typically on port 8300, did not limit request header size before processing, so a client that completes the internal RPC mTLS handshake can exhaust server memory before method validation or ACL evaluation, without holding an ACL token. The score is HashiCorp's as the CNA.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul and Consul Enterprise 1.21.0 through 2.0.3, you need this patch. Book a discovery call to get covered.