CVE-2026-19113: Unauthenticated denial of service via unbounded request body processing
Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was rejected. This vulnerability, CVE-2026-19113, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Consul Community Editionto a version that resolves this vulnerability.Fixed in 2.0.3 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.21.17 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 1.22.11 - Upgrade
Upgrade
Consul Enterpriseto a version that resolves this vulnerability.Fixed in 2.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19113?
CVE-2026-19113 has a medium severity level with a score of 5.3.
How does CVE-2026-19113 affect HashiCorp Consul?
CVE-2026-19113 allows unauthenticated denial of service by causing substantial memory consumption in several agent HTTP API endpoints.
Who is affected by CVE-2026-19113?
CVE-2026-19113 impacts users of HashiCorp Consul Community Edition and Consul Enterprise versions 1.3.0 through 2.0.2.
How do I fix CVE-2026-19113?
To mitigate CVE-2026-19113, upgrade to a later version of HashiCorp Consul that addresses this vulnerability.
What kind of attack does CVE-2026-19113 enable?
CVE-2026-19113 enables an unauthenticated denial of service attack affecting memory resources.