Skip to content
consulGHSA-23jv-v6qj-3fhh

Denial of Service (DoS) in HashiCorp Consul

High7.5CVE-2020-7219 · Published May 18, 2021 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
< 1.6.31.6.3
Details and references

HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3. ### Specific Go Packages Affected github.com/hashicorp/consul/agent/consul

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-770
Also known as
BIT-consul-2020-7219, CVE-2020-7219, GO-2022-0776

More consul advisories

All
DateAdvisory
May 182021Improper Input Validation in HashiCorp Consul
CVE-2020-13170Medium5.3fixed in 1.6.6, 1.7.4
May 182021Allocation of Resources Without Limits or Throttling in Hashicorp Consul
CVE-2020-13250High7.5fixed in 1.6.6, 1.7.4
Jun 232021Incorrect Permission Assignment for Critical Resource in Hashicorp Consul
CVE-2020-12797Medium5.3fixed in 1.6.6, 1.7.4
Jul 192021Hashicorp Consul Missing SSL Certificate Validation
CVE-2021-32574High7.5fixed in 1.10.1
Jul 192021HashiCorp Consul L7 deny intention results in an allow action
CVE-2021-36213High7.5fixed in 1.10.1
Jul 282021Incorrect Authorization in HashiCorp Consul
CVE-2020-7955Medium5.3fixed in 1.6.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.