BIT-consul-2026-19113

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/consul/BIT-consul-2026-19113.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-consul-2026-19113
Aliases
Published
2026-08-17T05:38:18.880Z
Modified
2026-08-17T08:00:26.944403335Z
Summary
Unauthenticated denial of service via unbounded request body processing
Details

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was rejected. This vulnerability, CVE-2026-19113, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Database specific
{
    "cpes": [
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:community:go:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / consul

Package

Name
consul
Purl
pkg:bitnami/consul

Severity

  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.3.0
Fixed
2.0.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/consul/BIT-consul-2026-19113.json"