Skip to content
ConsulGHSA-7g3r-8c6v-hfmr

Consul key/value endpoint is vulnerable to denial of service

Medium6.5CVE-2025-11374 · Published Oct 28, 2025 · updated Sep 10, 2026

Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
< 1.22.01.22.0
Details and references

More Consul advisories

All Consul
Advisory
Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication
Medium6.8Mar 12
Consul event endpoint is vulnerable to denial of service
Medium6.5Oct 28, 2025
Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability
Medium8.3Oct 31, 2024
Hashicorp Consul Cross-site Scripting vulnerability
Medium6.1Oct 31, 2024
Hashicorp Consul Path Traversal vulnerability
High8.1Oct 31, 2024
Privilege Escalation in HashiCorp Consul
Medium6.5Jan 31, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.