Skip to content
consulGHSA-chgm-7r52-whjj

Hashicorp Consul Path Traversal vulnerability

High8.1CVE-2024-10005 · Published Oct 31, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.9.0, < 1.20.11.20.1
Details and references

A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
BIT-consul-2024-10005, CVE-2024-10005, GO-2024-3243

More consul advisories

All
DateAdvisory
Oct 312024Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability
CVE-2024-10006Medium8.3fixed in 1.20.1
Oct 312024Hashicorp Consul Cross-site Scripting vulnerability
CVE-2024-10086Medium6.1fixed in 1.20.0
Jan 312024Privilege Escalation in HashiCorp Consul
CVE-2020-28053Medium6.5fixed in 1.6.10, 1.7.10, 1.8.6
Jan 312024Denial of service in HashiCorp Consul
CVE-2020-25201High7.5fixed in 1.7.9, 1.8.5
Oct 282025Consul key/value endpoint is vulnerable to denial of service
CVE-2025-11374Medium6.5fixed in 1.22.0
Oct 282025Consul event endpoint is vulnerable to denial of service
CVE-2025-11375Medium6.5fixed in 1.22.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.