CVE-2026-15972: Unauthenticated denial of service via unbounded external gRPC connection acceptance
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections, potentially preventing legitimate clients from connecting. This vulnerability, CVE-2026-15972, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Consul Community Edition/Consul Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.3Patch CVE-2026-15972 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.17Patch CVE-2026-15972 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.22.11Patch CVE-2026-15972
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15972?
CVE-2026-15972 has a severity rating of 7.5, classified as high.
What systems are affected by CVE-2026-15972?
CVE-2026-15972 affects Consul Community Edition and Consul Enterprise versions 1.13.0 through 2.0.2.
How do I fix CVE-2026-15972?
To fix CVE-2026-15972, upgrade to versions of Consul that are higher than 2.0.2, which contain the necessary security patches.
What type of attack does CVE-2026-15972 enable?
CVE-2026-15972 enables an unauthenticated denial of service attack by allowing a remote attacker to exhaust system resources.
What is the impact of CVE-2026-15972 on affected systems?
CVE-2026-15972 can lead to exhaustion of agent file descriptors, goroutines, and memory, potentially causing service interruption.