
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19113 is an unauthenticated denial of service vulnerability affecting HashiCorp Consul Community Edition and Consul Enterprise versions 1.3.0 through 2.0.2. The flaw exists in several agent HTTP API endpoints, where a remote caller can cause the agent to consume substantial memory before the request is rejected. It was published on August 7, 2026, and is classified as CWE-400 (Uncontrolled Resource Consumption). It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, HashiCorp Advisory).
The root cause is uncontrolled resource consumption (CWE-400) in multiple Consul agent HTTP API endpoints, where the agent allocates and processes memory for incoming requests without sufficient early validation or size limits, allowing the memory to grow substantially before the request is ultimately rejected. Because no authentication is required to reach these endpoints, any network-accessible attacker can trigger the condition. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it straightforward to automate (GitHub Advisory, HashiCorp Advisory).
Successful exploitation causes the Consul agent to consume substantial memory, leading to degraded performance or complete service unavailability on the affected node. Because Consul is a critical service mesh and service discovery component, disruption of its agents can cascade to dependent services that rely on health checks, configuration, and service registration. There is no impact on confidentiality or integrity; the vulnerability is limited to availability (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (HashiCorp Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.29%, placing it in the 22nd percentile for exploitation likelihood within 30 days. NVD SSVC assessment notes the attack is automatable with partial technical impact (GitHub Advisory).
top, htop, or APM agents); potential OOM (out-of-memory) kills of the Consul process in system logs (/var/log/syslog or dmesg).HashiCorp has released patched versions: Consul Community Edition 2.0.3, and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. Organizations should upgrade to one of these versions as the primary remediation. As interim workarounds, restrict network access to Consul agent HTTP API endpoints using firewalls or network policies to trusted hosts only, and consider implementing rate limiting or request filtering on the affected endpoints (HashiCorp Advisory, GitHub Advisory).
HashiCorp disclosed this vulnerability as part of a broader security advisory (HCSEC-2026-25) covering multiple vulnerabilities impacting Consul, published on their community discussion forum (HashiCorp Advisory). Tenable released a Nessus detection plugin (ID 333557) for this vulnerability shortly after disclosure (Tenable Plugin). No significant broader community or social media commentary has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."