ConsulGHSA-99wr-c2px-grmh
Hashicorp Consul Cross-site Scripting vulnerability
Medium6.1CVE-2024-10086 · Published Oct 31, 2024 · updated Sep 10, 2026
A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.4.1, < 1.20.0 | 1.20.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- BIT-consul-2024-10086, CVE-2024-10086, GO-2024-3242
- nvd.nist.gov/vuln/detail/CVE-2024-10086
- github.com/hashicorp/consul/commit/07fae7bb0be8593cc98c38b1ef4a49ed9188932f
- discuss.hashicorp.com/t/hcsec-2024-24-consul-vulnerable-to-reflected-xss-on-content-type-error-manipulation
- github.com/advisories/GHSA-99wr-c2px-grmh
- github.com/hashicorp/consul
- security.netapp.com/advisory/ntap-20250110-0006
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 282025 | Consul event endpoint is vulnerable to denial of service | Medium6.5 | 1.22.0 |
| Oct 282025 | Consul key/value endpoint is vulnerable to denial of service | Medium6.5 | 1.22.0 |
| Oct 312024 | Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability | Medium8.3 | 1.20.1 |
| Oct 312024 | Hashicorp Consul Path Traversal vulnerability | High8.1 | 1.20.1 |
| Jan 312024 | Privilege Escalation in HashiCorp Consul | Medium6.5 | 1.6.10+2 more |
| Jan 312024 | Denial of service in HashiCorp Consul | High7.5 | 1.7.9+1 more |