CVE-2026-19113
Consul vulnerability analysis and mitigation

Overview

CVE-2026-19113 is an unauthenticated denial of service vulnerability affecting HashiCorp Consul Community Edition and Consul Enterprise versions 1.3.0 through 2.0.2. The flaw exists in several agent HTTP API endpoints, where a remote caller can cause the agent to consume substantial memory before the request is rejected. It was published on August 7, 2026, and is classified as CWE-400 (Uncontrolled Resource Consumption). It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, HashiCorp Advisory).

Technical details

The root cause is uncontrolled resource consumption (CWE-400) in multiple Consul agent HTTP API endpoints, where the agent allocates and processes memory for incoming requests without sufficient early validation or size limits, allowing the memory to grow substantially before the request is ultimately rejected. Because no authentication is required to reach these endpoints, any network-accessible attacker can trigger the condition. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it straightforward to automate (GitHub Advisory, HashiCorp Advisory).

Impact

Successful exploitation causes the Consul agent to consume substantial memory, leading to degraded performance or complete service unavailability on the affected node. Because Consul is a critical service mesh and service discovery component, disruption of its agents can cascade to dependent services that rely on health checks, configuration, and service registration. There is no impact on confidentiality or integrity; the vulnerability is limited to availability (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (HashiCorp Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.29%, placing it in the 22nd percentile for exploitation likelihood within 30 days. NVD SSVC assessment notes the attack is automatable with partial technical impact (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Consul agent instances running versions 1.3.0 through 2.0.2 using tools like Shodan, Censys, or internal network scanning targeting the default Consul HTTP API port (8500).
  2. Identify vulnerable endpoints: Determine which agent HTTP API endpoints are exposed and susceptible to the memory consumption issue (specific endpoints are not publicly detailed beyond "several agent HTTP API endpoints").
  3. Send crafted requests: Repeatedly send unauthenticated HTTP requests with large or malformed payloads to the vulnerable agent API endpoints, causing the agent to allocate substantial memory for each request before rejection.
  4. Trigger resource exhaustion: By sending a high volume of such requests (potentially automated/scripted), exhaust the agent's available memory, causing degraded performance or a crash of the Consul agent process, resulting in denial of service for dependent services (HashiCorp Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unusual volume of unauthenticated HTTP requests to the Consul agent API port (default 8500) from external or unexpected source IPs; repeated large or malformed HTTP requests to agent API endpoints.
  • Logs: Consul agent logs showing a high rate of rejected requests or memory allocation errors; access logs with anomalous request sizes or frequencies to agent HTTP API paths.
  • Process: Consul agent process exhibiting abnormally high memory consumption as observed via system monitoring tools (e.g., top, htop, or APM agents); potential OOM (out-of-memory) kills of the Consul process in system logs (/var/log/syslog or dmesg).
  • Availability: Sudden unavailability or degraded responsiveness of Consul-dependent services; failed health checks reported by Consul for registered services.

Mitigation and workarounds

HashiCorp has released patched versions: Consul Community Edition 2.0.3, and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. Organizations should upgrade to one of these versions as the primary remediation. As interim workarounds, restrict network access to Consul agent HTTP API endpoints using firewalls or network policies to trusted hosts only, and consider implementing rate limiting or request filtering on the affected endpoints (HashiCorp Advisory, GitHub Advisory).

Community reactions

HashiCorp disclosed this vulnerability as part of a broader security advisory (HCSEC-2026-25) covering multiple vulnerabilities impacting Consul, published on their community discussion forum (HashiCorp Advisory). Tenable released a Nessus detection plugin (ID 333557) for this vulnerability shortly after disclosure (Tenable Plugin). No significant broader community or social media commentary has been identified beyond standard vulnerability database aggregation.

Additional resources


SourceThis report was generated using AI

Related Consul vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19017MEDIUM6.8
  • Grafana logoGrafana
  • grafana
NoYesAug 07, 2026
CVE-2026-19113MEDIUM5.3
  • Consul logoConsul
  • consul
NoYesAug 07, 2026
CVE-2026-19015MEDIUM5.3
  • Consul logoConsul
  • cpe:2.3:a:hashicorp:consul
NoYesAug 07, 2026
CVE-2026-19014MEDIUM4.3
  • Grafana logoGrafana
  • grafana.src
NoYesAug 07, 2026
CVE-2026-19016MEDIUM4.2
  • Grafana logoGrafana
  • consul-fips-2.0
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management