HashiCorpCVE-2026-16328
HashiCorp Tooling: server-side request forgery
High8.6CVE-2026-16328 · Published Jul 29, 2026 · updated Jul 30, 2026
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Tooling Product | >= 0.1.0, < 0.1.4 | 0.1.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
More HashiCorp advisories
All HashiCorp| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 7 | HashiCorp Consul: denial of service | Medium5.3 | 2.0.3+1 more |
| Aug 7 | Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are... | Medium4.2 | 2.0.3+1 more |
| Jul 29 | In consul-mcp-server | Critical10.0 | 0.1.4 |
| Jul 28 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant... | Critical10.0 | 1.1.0 |
| Jul 28 | HashiCorp Tooling: server-side request forgery | High8.6 | 1.1.0 |
| Jul 28 | HashiCorp Tooling: session fixation | High8.9 | 1.1.0 |