GHSA-cpfq-66p2-336j

Suggest an improvement
Source
https://github.com/advisories/GHSA-cpfq-66p2-336j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-cpfq-66p2-336j/GHSA-cpfq-66p2-336j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cpfq-66p2-336j
Aliases
Downstream
Published
2026-03-12T00:31:17Z
Modified
2026-03-24T21:17:32Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication
Details

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

Database specific
{
    "cwe_ids": [
        "CWE-59"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-12T17:34:04Z",
    "nvd_published_at": "2026-03-12T00:16:11Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/hashicorp/consul

Package

Name
github.com/hashicorp/consul
View open source insights on deps.dev
Purl
pkg:golang/github.com/hashicorp/consul

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.18.21

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-cpfq-66p2-336j/GHSA-cpfq-66p2-336j.json"

Go / github.com/hashicorp/consul

Package

Name
github.com/hashicorp/consul
View open source insights on deps.dev
Purl
pkg:golang/github.com/hashicorp/consul

Affected ranges

Type
SEMVER
Events
Introduced
1.22.0-rc1
Fixed
1.22.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-cpfq-66p2-336j/GHSA-cpfq-66p2-336j.json"

Go / github.com/hashicorp/consul

Package

Name
github.com/hashicorp/consul
View open source insights on deps.dev
Purl
pkg:golang/github.com/hashicorp/consul

Affected ranges

Type
SEMVER
Events
Introduced
1.19.0
Fixed
1.21.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-cpfq-66p2-336j/GHSA-cpfq-66p2-336j.json"