Skip to content
ConsulGHSA-99wr-c2px-grmh

Hashicorp Consul Cross-site Scripting vulnerability

Medium6.1CVE-2024-10086 · Published Oct 31, 2024 · updated Sep 10, 2026

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.4.1, < 1.20.01.20.0
Details and references

More Consul advisories

All Consul
Advisory
Consul event endpoint is vulnerable to denial of service
Medium6.5Oct 28, 2025
Consul key/value endpoint is vulnerable to denial of service
Medium6.5Oct 28, 2025
Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability
Medium8.3Oct 31, 2024
Hashicorp Consul Path Traversal vulnerability
High8.1Oct 31, 2024
Privilege Escalation in HashiCorp Consul
Medium6.5Jan 31, 2024
Denial of service in HashiCorp Consul
High7.5Jan 31, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.