Impact
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token.
Affected Systems
Affected products include HashiCorp Consul and HashiCorp Consul Enterprise. Vulnerable implementations are before Consul 2.0.4 and before Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. Because the EPSS score is not available and the request is not listed in CISA KEV, the likelihood of immediate exploitation cannot be determined from the provided data. The attack requires a client that can perform the internal RPC mTLS handshake, suggesting that network access to the native RPC listener by an authenticated user, or by a client that can complete the handshake without a valid ACL token, is sufficient to trigger the denial of service.
OpenCVE Enrichment