consulGHSA-qh7p-pfq3-677h
Consul event endpoint is vulnerable to denial of service
Medium6.5CVE-2025-11375 · Published Oct 28, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | < 1.22.0 | 1.22.0 |
Details and references
Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-770
- Also known as
- BIT-consul-2025-11375, CVE-2025-11375, GO-2025-4082
- nvd.nist.gov/vuln/detail/CVE-2025-11375
- github.com/hashicorp/consul/pull/22836
- github.com/hashicorp/consul/commit/e794201d0c618333d81ad775270f7b32801178fb
- discuss.hashicorp.com/t/hcsec-2025-28-consuls-event-endpoint-is-vulnerable-to-denial-of-service/76723
- github.com/hashicorp/consul
- github.com/hashicorp/consul/releases/tag/v1.22.0
- pkg.go.dev/vuln/GO-2025-4082
More consul advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 282025 | Consul key/value endpoint is vulnerable to denial of service CVE-2025-11374Medium6.5fixed in 1.22.0 | Medium6.5 | 1.22.0 |
| Mar 12 | Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication CVE-2026-2808Medium6.8fixed in 1.18.21, 1.21.11, 1.22.5 | Medium6.8 | 1.18.21, 1.21.11, 1.22.5 |
| Oct 312024 | Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability CVE-2024-10006Medium8.3fixed in 1.20.1 | Medium8.3 | 1.20.1 |
| Oct 312024 | Hashicorp Consul Cross-site Scripting vulnerability CVE-2024-10086Medium6.1fixed in 1.20.0 | Medium6.1 | 1.20.0 |
| Oct 312024 | Hashicorp Consul Path Traversal vulnerability CVE-2024-10005High8.1fixed in 1.20.1 | High8.1 | 1.20.1 |
| Jan 312024 | Privilege Escalation in HashiCorp Consul CVE-2020-28053Medium6.5fixed in 1.6.10, 1.7.10, 1.8.6 | Medium6.5 | 1.6.10, 1.7.10, 1.8.6 |