Description
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-190124, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Published: 2026-08-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncontrolled resource consumption flaw exists within the Consul Connect authorization endpoint, allowing a caller to grow the agent’s intention‑match cache without bound. The vulnerability defeats the operator’s cache‑disable configuration and can lead to excessive memory or disk use, potentially causing the Consul agent to become unresponsive or crash. The weakness is a classic example of CWE‑770, Uncontrolled Resource Consumption.

Affected Systems

HashiCorp Consul Community Edition and Consul Enterprise versions 1.17.0 through 2.0.2 are affected. The issue has been fixed in Consul 2.0.3, and in Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity assessment. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via the Connect authorization endpoint, which may be reachable from the network or through external clients. An attacker with access to that endpoint can send repeated or specially crafted requests to expand the cache until the agent’s resources are exhausted. Because the flaw can be triggered with normal endpoint access and without privileged credentials, the exploitation difficulty is considered low to moderate. The risk is chiefly availability impact to the Consul agent, which can cascade to service disruptions in systems relying on Consul for service discovery and configuration.

Generated by OpenCVE AI on August 7, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Consul 2.0.3 (Community) or Consul Enterprise 1.21.17, 1.22.11, or 2.0.3, which contain the fix for the cache‑growth flaw.
  • Control access to the Connect authorization endpoint, for example by applying ACLs or firewall rules to limit request traffic to trusted hosts only.
  • Monitor agent resource metrics for abnormal cache growth and configure alerts to detect rapid increases in cache usage.

Generated by OpenCVE AI on August 7, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Hashicorp consul Enterprise
Vendors & Products Hashicorp
Hashicorp consul
Hashicorp consul Enterprise

Fri, 07 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-190124, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Title Uncontrolled resource consumption in the Consul Connect authorization endpoint
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Hashicorp Consul Consul Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-08-10T18:24:35.830Z

Reserved: 2026-08-05T20:21:24.334Z

Link: CVE-2026-19014

cve-icon Vulnrichment

Updated: 2026-08-10T17:45:08.099Z

cve-icon NVD

Status : Received

Published: 2026-08-07T20:16:50.273

Modified: 2026-08-10T19:17:29.410

Link: CVE-2026-19014

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-07T19:19:05Z

Links: CVE-2026-19014 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T21:00:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling