BIT-consul-2026-15972

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/consul/BIT-consul-2026-15972.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-consul-2026-15972
Aliases
Published
2026-08-17T05:38:03.657Z
Modified
2026-08-17T08:00:08.510229863Z
Summary
Unauthenticated denial of service via unbounded external gRPC connection acceptance
Details

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections, potentially preventing legitimate clients from connecting. This vulnerability, CVE-2026-15972, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Database specific
{
    "cpes": [
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:community:go:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / consul

Package

Name
consul
Purl
pkg:bitnami/consul

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.13.0
Fixed
2.0.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/consul/BIT-consul-2026-15972.json"