Uncontrolled Resource Consumption in Consul Connect Auth Endpt 1.17-2.0.2
CVE-2026-19014 Published on August 7, 2026

Uncontrolled resource consumption in the Consul Connect authorization endpoint
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-190124, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

NVD

Weakness Type

Allocation of Resources Without Limits or Throttling

The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.


Products Associated with CVE-2026-19014

Want to know whenever a new CVE is published for HashiCorp Consul? stack.watch will email you.

 

Affected Versions

HashiCorp Consul: HashiCorp Consul Enterprise: