CVE-2026-88021
- EPSS 0.24%
- Veröffentlicht 10.09.2026 19:17:39
- Zuletzt bearbeitet 10.09.2026 20:17:31
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul di...
CVE-2026-87107
- EPSS 0.23%
- Veröffentlicht 10.09.2026 19:17:37
- Zuletzt bearbeitet 10.09.2026 20:17:29
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may explo...
CVE-2026-87106
- EPSS 0.24%
- Veröffentlicht 10.09.2026 18:55:15
- Zuletzt bearbeitet 10.09.2026 19:45:14
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS hand...
CVE-2026-87090
- EPSS 0.21%
- Veröffentlicht 10.09.2026 18:54:45
- Zuletzt bearbeitet 10.09.2026 19:45:14
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token gra...
CVE-2026-19113
- EPSS 0.29%
- Veröffentlicht 07.08.2026 19:20:32
- Zuletzt bearbeitet 28.08.2026 15:47:00
Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was ...
CVE-2026-15972
- EPSS 0.39%
- Veröffentlicht 07.08.2026 19:20:22
- Zuletzt bearbeitet 28.08.2026 15:47:00
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, g...
CVE-2026-15970
- EPSS 0.16%
- Veröffentlicht 07.08.2026 19:20:13
- Zuletzt bearbeitet 28.08.2026 15:47:00
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are ...
CVE-2026-19017
- EPSS 0.33%
- Veröffentlicht 07.08.2026 19:19:20
- Zuletzt bearbeitet 28.08.2026 15:47:00
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` ...
CVE-2026-19015
- EPSS 0.29%
- Veröffentlicht 07.08.2026 19:19:11
- Zuletzt bearbeitet 28.08.2026 15:47:00
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, ...
CVE-2026-19014
- EPSS 0.26%
- Veröffentlicht 07.08.2026 19:19:05
- Zuletzt bearbeitet 28.08.2026 15:47:00
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, de...