CVE-2025-11375: Consul's event endpoint is vulnerable to denial of service
Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11375?
CVE-2025-11375 is classified as a denial of service (DoS) vulnerability.
How do I fix CVE-2025-11375?
To mitigate CVE-2025-11375, upgrade to Consul Community Edition 1.22.0 or Consul Enterprise versions 1.22.0, 1.21.6, or 1.20.8.
What versions are affected by CVE-2025-11375?
CVE-2025-11375 affects HashiCorp Consul versions up to but not including 1.22.0 and Consul Enterprise versions 1.18.12 up to but not including 1.22.0.
What is the risk of not addressing CVE-2025-11375?
Failing to address CVE-2025-11375 may leave your Consul setup vulnerable to denial of service attacks, potentially disrupting service availability.
Is CVE-2025-11375 present in all Consul versions?
No, CVE-2025-11375 is only present in specific earlier versions of HashiCorp Consul and Consul Enterprise prior to their fixed releases.