CVE-2026-15972

Source
https://cve.org/CVERecord?id=CVE-2026-15972
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15972.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15972
Downstream
Published
2026-08-07T19:20:22.442Z
Modified
2026-08-11T03:30:44.451756002Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Unauthenticated denial of service via unbounded external gRPC connection acceptance
Details

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections, potentially preventing legitimate clients from connecting. This vulnerability, CVE-2026-15972, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15972.json",
    "cna_assigner": "HashiCorp",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.13.0"
                },
                {
                    "fixed": "2.0.3"
                },
                {
                    "introduced": "1.13.0"
                },
                {
                    "fixed": "2.0.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events
Database specific
Show details
{
    "source": "DESCRIPTION",
    "extracted_events": [
        {
            "introduced": "1.13.0"
        },
        {
            "fixed": "2.0.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15972.json"