Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication in github.com/hashicorp/consul
{ "url": "https://pkg.go.dev/vuln/GO-2026-4690", "review_status": "REVIEWED" }
{ "custom_ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "1.18.21" }, { "introduced": "1.19.0" }, { "fixed": "1.21.11" }, { "introduced": "1.22.0-rc1" }, { "fixed": "1.22.5" } ] } ] }
"https://vuln.go.dev/ID/GO-2026-4690.json"