CVE-2026-19113

Source
https://cve.org/CVERecord?id=CVE-2026-19113
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19113.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19113
Downstream
Published
2026-08-07T19:20:32.261Z
Modified
2026-08-09T03:30:15.808150376Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Unauthenticated denial of service via unbounded request body processing
Details

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was rejected. This vulnerability, CVE-2026-19113, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.3.0"
                },
                {
                    "fixed": "2.0.3"
                },
                {
                    "introduced": "1.3.0"
                },
                {
                    "fixed": "2.0.3"
                }
            ]
        }
    ],
    "cna_assigner": "HashiCorp",
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19113.json"
}
References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events
Database specific
{
    "source": "DESCRIPTION",
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "fixed": "2.0.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19113.json"