Sceawere

Vulnerability Detail

CVE-2026-19015UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Consul Connect CA Uncontrolled Resource Consumption

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
17h ago
Vendor
HashiCorp
Product
Consul
Attack Type
CWE-770: Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-07T20:16:50.403Z",
  "pubdate": "2026-08-07T20:16:50.403Z",
  "executiveSummary": "Consul Community Edition and Consul Enterprise are affected by an uncontrolled resource consumption vulnerability within the Connect CA roots endpoint, designated as CVE-2026-19015. This vulnerability allows a remote caller to indefinitely grow the agent's Connect CA roots cache without bound, effectively bypassing and defeating any operator-configured cache-disable settings. The flaw exposes affected systems to denial-of-service conditions through memory exhaustion as unconstrained data accumulates within the agent process. Remote attackers with network access to the vulnerable endpoint can trigger the resource exhaustion condition without requiring specialized authentication or elevated privileges beyond the ability to interact with the target endpoint. Remediation requires upgrading to the patched software versions provided by the vendor, as no explicit configuration workarounds are described to neutralize the caching flaw directly.",
  "technicalDetails": "The vulnerability resides in the Connect CA roots endpoint of Consul Community Edition and Consul Enterprise versions 1.2.0 through 2.0.2. The root cause stems from improper management and unbounded growth of internal caching structures associated with Connect Certificate Authority root certificates. Specifically, the agent fails to enforce proper boundary constraints or honor the operator's cache-disable configuration when processing requests targeting the Connect CA roots endpoint. Attackers leverage this flaw by sending a continuous stream of specially crafted or distinct requests that force the Consul agent to allocate and store new cache entries indefinitely. Because the implementation lacks garbage collection, rate-limiting, or size restrictions on this specific cache, memory consumption scales linearly with malicious input until the host system encounters resource depletion, leading to process termination or severe performance degradation of the Consul agent. The vulnerable component is network-exposed via the agent API endpoints handling Connect CA root operations. Exploitation can be executed remotely by any caller capable of reaching the vulnerable endpoint over the network. Authentication and privilege requirements are minimal, as the endpoint processes requests that can drive cache allocation without strict prerequisite authorization checks in vulnerable configurations. The post-exploitation impact is strictly localized to denial of service via memory exhaustion, disrupting service discovery, mesh networking, and internal cryptographic operations managed by the affected Consul agent."
}
CVE-2026-19015: Consul Connect CA Uncontrolled Resource Consumption (MEDIUM Severity, CVSS: 5.3) - Sceawere