Skip to content
ConsulGHSA-cpfq-66p2-336j

Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication

Medium6.8CVE-2026-2808 · Published Mar 12, 2026 · updated Mar 24, 2026

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
< 1.18.211.18.21
>= 1.22.0-rc1, < 1.22.51.22.5
>= 1.19.0, < 1.21.111.21.11
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-59
Also known as
BIT-consul-2026-2808, CVE-2026-2808, GO-2026-4690

More Consul advisories

All Consul
Advisory
Consul key/value endpoint is vulnerable to denial of service
Medium6.5Oct 28, 2025
Consul event endpoint is vulnerable to denial of service
Medium6.5Oct 28, 2025
Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability
Medium8.3Oct 31, 2024
Hashicorp Consul Cross-site Scripting vulnerability
Medium6.1Oct 31, 2024
Hashicorp Consul Path Traversal vulnerability
High8.1Oct 31, 2024
Privilege Escalation in HashiCorp Consul
Medium6.5Jan 31, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.