Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-87106
Consul: native RPC listener memory exhaustion before ACL checks
Technology
HashiCorp Consul
CVSS Score
6.5 / 10.0
Affected Versions
Consul and Consul Enterprise 1.21.0 through 2.0.3
Upstream Fix
2.0.4; Enterprise 1.21.18, 1.22.12
Published
September 10, 2026
OSSeva Coverage
Fixed upstream
Description
The native RPC request decoder, typically on port 8300, did not limit request header size before processing, so a client that completes the internal RPC mTLS handshake can exhaust server memory before method validation or ACL evaluation, without holding an ACL token. The score is HashiCorp's as the CNA.
Is your HashiCorp Consul deployment affected?
If you're running Consul and Consul Enterprise 1.21.0 through 2.0.3, you need this patch. Book a discovery call to get covered.