📦 Consul

by Hashicorp

🔍 What is Consul?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-2816

HIGH CVSS 8.7 Jun 2, 2023

This vulnerability allows users with service:write permissions in Consul to modify Envoy proxy configurations for downstream services they don't own. Attackers could redirect, intercept, or manipulate...

CVE-2021-32574

HIGH CVSS 7.5 Jul 17, 2021

This vulnerability in HashiCorp Consul's Envoy proxy allows TLS connections to bypass service identity validation. Attackers could potentially intercept or manipulate traffic between services by imper...

CVE-2021-28156

HIGH CVSS 7.5 Apr 20, 2021

This vulnerability allows attackers to bypass audit logging in HashiCorp Consul Enterprise by sending specifically crafted HTTP events. This affects Consul Enterprise versions 1.8.0 through 1.9.4, pot...

CVE-2025-11374

MEDIUM CVSS 6.5 Oct 28, 2025

Consul's key/value endpoint is vulnerable to denial of service due to incorrect Content Length header validation. Attackers can send malformed requests to crash or degrade Consul service availability....

CVE-2025-11375

MEDIUM CVSS 6.5 Oct 28, 2025

Consul's event endpoint is vulnerable to denial of service (DoS) attacks due to lack of validation on Content-Length headers, allowing attackers to send excessively large requests that consume server ...