6.5
CVE-2026-87106
- EPSS 0.24%
- Veröffentlicht 10.09.2026 18:55:15
- Zuletzt bearbeitet 10.09.2026 19:45:14
- Erkennungen
Consul vulnerable to a denial of service in the native RPC listener
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This vulnerability (CVE-2026-87106) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerHashiCorp
≫
Produkt
Consul
Default Statusunaffected
Version
1.21.0
Version <
2.0.4
Status
affected
HerstellerHashiCorp
≫
Produkt
Consul Enterprise
Default Statusunaffected
Version
1.21.0
Version <
2.0.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.144 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@hashicorp.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://discuss.hashicorp.com/t/hcsec-2026-35-consul-vulnerable-to-a-denial-of-service-in-the-native-rpc-listener/77737