VDB
Sign up
MEDIUM6.5

GHSA-7g3r-8c6v-hfmr

Consul key/value endpoint is vulnerable to denial of service

Quick fix

GHSA-7g3r-8c6v-hfmr — github.com/hashicorp/consul: upgrade to the fixed version with the command below.

go get github.com/hashicorp/consul@v1.22.0

Details

Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/consul
Introduced in: 0Fixed in: 1.22.0
Fixgo get github.com/hashicorp/consul@v1.22.0

References