CVE-2026-19012: Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path
Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul server. A caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This vulnerability, CVE-2026-19012, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Consulto a version that resolves this vulnerability.Fixed in 2.0.3 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.17 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.22.11 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.3 - Compensating control
Restrict access to the service-router configuration entry functionality to trusted callers only, since an authenticated caller with config-entry write permission can submit a configuration entry that crashes the Consul server (CVE-2026-19012).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19012?
The severity of CVE-2026-19012 is medium with a CVSS score of 5.3.
How do I fix CVE-2026-19012?
To fix CVE-2026-19012, update to a version of Consul that is not vulnerable, specifically above 2.0.2.
What type of vulnerability is CVE-2026-19012?
CVE-2026-19012 is categorized as an authenticated denial of service vulnerability.
Who is affected by CVE-2026-19012?
CVE-2026-19012 affects users of HashiCorp Consul Community Edition and Consul Enterprise versions 1.18.0 through 2.0.2.
What can an attacker do with CVE-2026-19012?
An attacker with config-entry write permissions can crash the Consul server through the downgrade path.