Description
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Consul Community Edition and Consul Enterprise versions 1.2.0 through 2.0.2 are vulnerable because the Connect CA roots endpoint allows a remote caller to grow the agent's Connect CA roots cache without limit. This uncontrolled resource consumption can lead to excessive memory usage that may crash or degrade the Consul agent, effectively causing a denial of service. The weakness is identified as CWE‑770.

Affected Systems

Affected products are HashiCorp Consul Community Edition and Consul Enterprise. Vulnerable releases include community editions from 1.2.0 to 2.0.2 and Enterprise editions up to 2.0.2. Fixes are available in Community 2.0.3 and Enterprise 1.21.17, 1.22.11, and 2.0.3.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS score is not available, and the vulnerability is not listed in CISA KEV, so current exploitation likelihood is uncertain. Attackers can exploit the endpoint remotely, with no special privileges, by repeatedly requesting the CA roots endpoint, causing the cache to grow until resources are exhausted. The impact is a service disruption that affects all agents using the vulnerable firmware. Prompt patching is recommended because unbounded cache growth can compromise system stability.

Generated by OpenCVE AI on August 7, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Consul Community Edition to 2.0.3 or later or upgrade Consul Enterprise to 1.21.17, 1.22.11, or 2.0.3.
  • Ensure the Connect CA roots cache is disabled if upgrading is not immediately possible.
  • Restrict access to the Connect CA roots endpoint to trusted internal networks or implement network-level rate limiting to mitigate resource exhaustion until a patch is applied.

Generated by OpenCVE AI on August 7, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Hashicorp consul Enterprise
Vendors & Products Hashicorp
Hashicorp consul
Hashicorp consul Enterprise

Fri, 07 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Title Uncontrolled resource consumption in the Consul Connect CA roots endpoint
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Hashicorp Consul Consul Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published:

Updated: 2026-08-07T19:19:11.407Z

Reserved: 2026-08-05T20:21:29.431Z

Link: CVE-2026-19015

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T20:30:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling