CVE-2026-15972

HashiCorp · Consul

HashiCorp Consul is vulnerable to an uncontrolled resource consumption issue due to inadequate limits on resource allocation, potentially leading to denial of service.

Executive summary

A high severity resource exhaustion vulnerability in HashiCorp Consul allows unauthenticated attackers to cause a denial of service.

Vulnerability

This vulnerability involves a failure to properly limit or throttle resource allocation (CWE-770). An unauthenticated attacker can exploit this to exhaust system resources, resulting in a denial of service for the affected Consul instance.

Business impact

Successful exploitation of this flaw can result in significant service disruption, as Consul is a critical component for service discovery and configuration management in many distributed environments. With a CVSS score of 7.5, the vulnerability poses a high risk to availability, potentially causing cascading failures in dependent microservices and infrastructure components.

Remediation

Immediate Action: Update both Consul and Consul Enterprise instances to version 2.0.3 or later immediately.

Proactive Monitoring: Monitor system resource metrics, such as CPU and memory usage, for sudden spikes that may indicate exploitation attempts.

Compensating Controls: Implement network access controls to restrict access to the Consul API to known, trusted management nodes.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical role Consul plays in infrastructure availability, administrators must prioritize patching this vulnerability. Apply the update to version 2.0.3 across all production environments to prevent potential service outages caused by resource exhaustion.