Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qh7p-pfq3-677h Consul event endpoint is vulnerable to denial of service
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 29 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Vendors & Products Hashicorp
Hashicorp consul

Tue, 28 Oct 2025 20:30:00 +0000

Type Values Removed Values Added
Description Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
Title Consul's event endpoint is vulnerable to denial of service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2025-10-29T17:34:25.690Z

Reserved: 2025-10-06T15:34:11.889Z

Link: CVE-2025-11375

cve-icon Vulnrichment

Updated: 2025-10-29T17:34:21.069Z

cve-icon NVD

Status : Received

Published: 2025-10-28T21:15:37.470

Modified: 2025-10-28T21:15:37.470

Link: CVE-2025-11375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-29T10:57:46Z