Skip to content
HashiCorpCVE-2026-16326

In consul-mcp-server

Critical10.0CVE-2026-16326 · Published Jul 29, 2026 · updated Jul 30, 2026

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Tooling
Product
>= 0.1.0, < 0.1.40.1.4
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Consul: denial of service
Medium5.3Aug 7
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are...
Medium4.2Aug 7
HashiCorp Tooling: server-side request forgery
High8.6Jul 29
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant...
Critical10.0Jul 28
HashiCorp Tooling: server-side request forgery
High8.6Jul 28
HashiCorp Tooling: session fixation
High8.9Jul 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.