Skip to content
ConsulGHSA-q7fx-wm2p-qfj8

HashiCorp Consul vulnerable to Origin Validation Error

High7.4CVE-2019-9764 · Published May 13, 2022 · updated Sep 10, 2026

HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if `verify_server_hostname` were set to false, even when it is actually set to true. This is fixed in 1.4.4.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
< 1.4.41.4.4
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-346
Also known as
CVE-2019-9764, GO-2023-1853

More Consul advisories

All Consul
Advisory
HashiCorp Consul Cross-site Scripting vulnerability
Medium6.1May 24, 2022
HashiCorp Consul can use cleartext agent-to-agent RPC communication
Medium5.9May 14, 2022
HashiCorp Consul Access Restriction Bypass
High8.1May 13, 2022
Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector
High7.5Apr 20, 2022
HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers
Medium6.5Feb 25, 2022
Denial of Service (DoS) in HashiCorp Consul
Medium5.3Feb 15, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.