Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16328— consul-mcp-server vulnerable to server side request forgery leading to token exposure

Quick assessment

Affected
HashiCorp Tooling
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

HashiCorp consul-mcp-server是美国HashiCorp公司的一款服务端软件产品。 HashiCorp consul-mcp-server 0.1.3及之前版本存在服务端请求伪造漏洞,该漏洞源于未限制Consul后端地址的提供方式,允许连接的客户端通过请求头覆盖服务器配置的Consul地址,可能导致恶意客户端将服务器的Consul API流量重定向到攻击者控制的端点,从而泄露服务器配置的Consul令牌。

CVSS 8.6 · High EPSS 0.23% · P14

Affected Version Matrix 1

VendorProduct Version RangeStatus
HashiCorp Tooling 0.1.0< 0.1.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16328

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
consul-mcp-server vulnerable to server side request forgery leading to token exposure
Source: CVE Program / CVE List V5
Vulnerability Description
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
HashiCorp consul-mcp-server 服务端请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HashiCorp consul-mcp-server是美国HashiCorp公司的一款服务端软件产品。 HashiCorp consul-mcp-server 0.1.3及之前版本存在服务端请求伪造漏洞,该漏洞源于未限制Consul后端地址的提供方式,允许连接的客户端通过请求头覆盖服务器配置的Consul地址,可能导致恶意客户端将服务器的Consul API流量重定向到攻击者控制的端点,从而泄露服务器配置的Consul令牌。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
HashiCorp Tooling 0.1.0 ~ 0.1.4 -

II. Public POCs for CVE-2026-16328

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16328

登录查看更多情报信息。

Vendor Advisories for CVE-2026-16328 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-16328

No comments yet


Leave a comment