CVE-2026-87106: CWE-400: Uncontrolled Resource Consumption in HashiCorp Consul
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This vulnerability (CVE-2026-87106) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
AI Analysis
Technical Summary
CVE-2026-87106 is an uncontrolled resource consumption vulnerability (CWE-400) in HashiCorp Consul's native RPC listener. An authenticated client able to complete the internal RPC mutual TLS handshake may exploit this flaw to exhaust server memory prior to ACL authorization evaluation, leading to denial of service. The vulnerability affects Consul versions >=1.21.0 and <2.0.4, and Consul Enterprise versions >=1.21.0 and <1.21.18. The issue is resolved in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4.
Potential Impact
Successful exploitation allows an authenticated client to cause a denial of service by exhausting server memory before ACL authorization is enforced. There is no impact on confidentiality or integrity. The CVSS v3.1 score is 6.5 (medium severity) reflecting network attack vector, low attack complexity, required privileges, no user interaction, and impact limited to availability.
Mitigation Recommendations
Upgrade affected Consul versions to 2.0.4 or later, and Consul Enterprise to 1.21.18, 1.22.12, 2.0.4 or later. These versions contain the official fix for this vulnerability. No other mitigations are indicated by the vendor advisory.
CVE-2026-87106: CWE-400: Uncontrolled Resource Consumption in HashiCorp Consul
Description
Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This vulnerability (CVE-2026-87106) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.
CVSS v3.1
Score 6.5medium
Affected software
HashiCorp
Consul
HashiCorp
Consul Enterprise
pkg:github/Consul EnterpriseRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-87106 is an uncontrolled resource consumption vulnerability (CWE-400) in HashiCorp Consul's native RPC listener. An authenticated client able to complete the internal RPC mutual TLS handshake may exploit this flaw to exhaust server memory prior to ACL authorization evaluation, leading to denial of service. The vulnerability affects Consul versions >=1.21.0 and <2.0.4, and Consul Enterprise versions >=1.21.0 and <1.21.18. The issue is resolved in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4.
Potential Impact
Successful exploitation allows an authenticated client to cause a denial of service by exhausting server memory before ACL authorization is enforced. There is no impact on confidentiality or integrity. The CVSS v3.1 score is 6.5 (medium severity) reflecting network attack vector, low attack complexity, required privileges, no user interaction, and impact limited to availability.
Mitigation Recommendations
Upgrade affected Consul versions to 2.0.4 or later, and Consul Enterprise to 1.21.18, 1.22.12, 2.0.4 or later. These versions contain the official fix for this vulnerability. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- HashiCorp
- Date Reserved
- 2026-09-08T20:19:26.410Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa2fed1d29482f9abff9625
Added to database: 09/10/2026, 19:02:41 UTC
Last enriched: 09/10/2026, 19:17:14 UTC
Last updated: 09/10/2026, 19:23:09 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.