CVE-2025-11375

Source
https://cve.org/CVERecord?id=CVE-2025-11375
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11375.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-11375
Aliases
Downstream
Related
Published
2025-10-28T20:12:14.325Z
Modified
2026-08-12T03:51:28.788669537Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Consul's event endpoint is vulnerable to denial of service
Details

Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11375.json",
    "cwe_ids": [
        "CWE-770"
    ],
    "cna_assigner": "HashiCorp"
}
References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.18.12"
        },
        {
            "fixed": "1.22.0"
        },
        {
            "introduced": "1.19.0"
        },
        {
            "fixed": "1.20.8"
        },
        {
            "introduced": "1.21.0"
        },
        {
            "fixed": "1.21.6"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

api/v1.*
api/v1.0.0
api/v1.0.1
api/v1.1.0
api/v1.10.0
api/v1.2.0
api/v1.32.0
api/v1.32.1
api/v1.32.4
api/v1.33.0-rc2
api/v1.4.0
internal/v0.*
internal/v0.1.0
Other
list
proto-public/v0.*
proto-public/v0.1.0
proto-public/v0.1.1
proto-public/v0.7.0
sdk/v0.*
sdk/v0.1.0
sdk/v0.1.1
sdk/v0.16.3
sdk/v0.17.0
sdk/v0.17.0-rc1
sdk/v0.2.0
sdk/v0.4.0
v0.*
v0.1.0
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.4.0
v0.4.1
v0.5.0
v0.5.0rc1
v0.5.1
v0.5.2
v0.6.0
v0.6.0-rc1
v0.6.0-rc2
v0.6.1
v0.6.3
v0.6.4
v0.6.4-rc3
v0.7.0
v0.7.0-rc1
v0.7.0-rc2
v0.7.1
v0.7.2
v0.7.2-rc1
v0.7.3
v0.7.4
v0.8.0
v0.8.0-rc1
v0.8.1
v0.8.2
v0.8.4
v0.8.5
v0.9.0
v0.9.0-rc1
v0.9.1
v0.9.2
v0.9.3
v0.9.3-rc1
v0.9.3-rc2
v1.*
v1.0.0
v1.0.0-beta1
v1.0.0-beta2
v1.0.1
v1.0.1-rc1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.1.0
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.4.0
v1.4.0-rc1
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.7.0
v1.7.0-beta1
v1.7.0-beta2
v1.7.0-beta3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11375.json"