CVE-2025-11374: Consul's KV endpoint is vulnerable to denial of service
Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11374?
CVE-2025-11374 has a high severity rating due to its potential to cause denial of service.
How do I fix CVE-2025-11374?
To fix CVE-2025-11374, upgrade to Consul Community Edition 1.22.0 or Consul Enterprise 1.22.0, 1.21.6, or 1.20.8.
Which versions of Consul are affected by CVE-2025-11374?
CVE-2025-11374 affects versions of Consul prior to 1.22.0 and Consul Enterprise between 1.18.12 and 1.22.0.
What is the impact of CVE-2025-11374 on my system?
The impact of CVE-2025-11374 on your system can lead to a denial of service, making the key/value endpoint unavailable.
Is there a workaround for CVE-2025-11374?
There is no official workaround for CVE-2025-11374; upgrading to the patched versions is recommended.