Consul 和 Consul Enterprise 的原生 RPC 监听器存在拒绝服务(DoS)漏洞,经过身份验证的客户端可能在 ACL 授权评估之前耗尽服务器内存。能够完成内部 RPC mTLS 握手的客户端,即使不持有有效的 ACL 令牌,也可能利用此漏洞。该漏洞(CVE-2026-87106)已在 Consul 2.0.4 以及 Consul Enterprise 1.21.18、1.22.12 和 2.0.4 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Consul | 1.21.0< 2.0.4 |
affected |
| HashiCorp | Consul Enterprise | 1.21.0< 2.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Consul | 1.21.0 ~ 2.0.4 | - |
|
| HashiCorp | Consul Enterprise | 1.21.0 ~ 2.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87090 | 8.3 HIGH | Consul vulnerable to an authorization bypass in the catalog node-write path |
| CVE-2026-87993 | 7.7 HIGH | Consul-template vulnerable to an information disclosure issue in error handling |
| CVE-2026-88021 | 7.5 HIGH | Consul vulnerable to an authorization bypass in the Connect service mesh |
| CVE-2026-87107 | 5.4 MEDIUM | Consul vulnerable to an authorization bypass in the catalog deregistration path |
No comments yet