CVE-2026-19015: Uncontrolled resource consumption in the Consul Connect CA roots endpoint
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
consulto a version that resolves this vulnerability.Fixed in 2.0.3 - Upgrade
Upgrade
consul enterpriseto a version that resolves this vulnerability.Fixed in 1.21.17 - Upgrade
Upgrade
consul enterpriseto a version that resolves this vulnerability.Fixed in 1.22.11 - Upgrade
Upgrade
consul enterpriseto a version that resolves this vulnerability.Fixed in 2.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19015?
The severity of CVE-2026-19015 is medium with a score of 5.3.
How does CVE-2026-19015 impact HashiCorp Consul?
CVE-2026-19015 allows uncontrolled resource consumption in the Consul Connect CA roots endpoint, potentially exhausting the agent's cache resources.
Which versions of Consul are affected by CVE-2026-19015?
CVE-2026-19015 affects HashiCorp Consul Community Edition and Consul Enterprise versions from 1.2.0 through 2.0.2.
How can I mitigate the risk of CVE-2026-19015 in my Consul deployment?
To mitigate CVE-2026-19015, ensure that you upgrade to a patched version of HashiCorp Consul beyond 2.0.2.
What are the consequences of CVE-2026-19015 if exploited?
Exploitation of CVE-2026-19015 can lead to resource exhaustion, compromising the performance of the Consul agent.