CVE-2026-19014 Details
Description
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-190124, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
A vulnerability allowing uncontrolled resource consumption has been identified in HashiCorp Consul Community Edition and Consul Enterprise versions 1.17.0 through 2.0.2. The issue arises in the Connect authorization endpoint, where a caller can increase the agent's intention-match cache without limit. This behavior undermines the operator's cache-disable configuration, as the endpoint fails to respect the 'http_config.use_cache' setting. Instead, it continues to use the intention-match cache, allowing a caller with 'service:write' permission to generate an unbounded number of distinct cache entries. The vulnerability is particularly concerning because it can lead to increased memory usage and degraded agent performance, with the cache growing indefinitely.
Users are advised to upgrade to Consul version 2.0.3 or, for Consul Enterprise, to versions 1.21.17, 1.22.11, or 2.0.3. In addition, enabling mutual TLS on the Consul server RPC port can help reduce the risk associated with this vulnerability by requiring valid client certificates for RPC access.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |