Skip to content
consulGHSA-qh7p-pfq3-677h

Consul event endpoint is vulnerable to denial of service

Medium6.5CVE-2025-11375 · Published Oct 28, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
< 1.22.01.22.0
Details and references

Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-770
Also known as
BIT-consul-2025-11375, CVE-2025-11375, GO-2025-4082

More consul advisories

All
DateAdvisory
Oct 282025Consul key/value endpoint is vulnerable to denial of service
CVE-2025-11374Medium6.5fixed in 1.22.0
Mar 12Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication
CVE-2026-2808Medium6.8fixed in 1.18.21, 1.21.11, 1.22.5
Oct 312024Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability
CVE-2024-10006Medium8.3fixed in 1.20.1
Oct 312024Hashicorp Consul Cross-site Scripting vulnerability
CVE-2024-10086Medium6.1fixed in 1.20.0
Oct 312024Hashicorp Consul Path Traversal vulnerability
CVE-2024-10005High8.1fixed in 1.20.1
Jan 312024Privilege Escalation in HashiCorp Consul
CVE-2020-28053Medium6.5fixed in 1.6.10, 1.7.10, 1.8.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.