|
HCSEC-2026-25 - Multiple vulnerabilities impacting HashiCorp Consul
|
|
0
|
359
|
August 7, 2026
|
|
HCSEC-2026-24 - Multiple vulnerabilities impacting HashiCorp Consul MCP Server
|
|
0
|
298
|
July 29, 2026
|
|
HCSEC-2026-20 - Consul-template vulnerable to path redirections in writeToFile
|
|
0
|
161
|
July 8, 2026
|
|
HCSEC-2026-18 - Memberlist vulnerable to denial of service via gossip message
|
|
0
|
195
|
July 8, 2026
|
|
HCSEC-2026-12 - Consul-template vulnerable to sandbox path bypass in file helper through symlink attack
|
|
0
|
253
|
May 12, 2026
|
|
HCSEC-2026-02 - Consul Vulnerable to Arbitrary File Reads Through the Vault Kubernetes Authentication Provider
|
|
0
|
485
|
March 11, 2026
|
|
HCSEC-2025-29 - Consul's KV endpoint is vulnerable to denial of service
|
|
0
|
992
|
October 28, 2025
|
|
HCSEC-2025-28 - Consul's event endpoint is vulnerable to denial of service
|
|
0
|
846
|
October 28, 2025
|
|
HCSEC-2024-24 - Consul Vulnerable To Reflected XSS On Content-Type Error Manipulation
|
|
0
|
1523
|
October 30, 2024
|
|
HCSEC-2024-23 - Consul L7 Intentions Vulnerable To Headers Bypass
|
|
0
|
1379
|
October 30, 2024
|
|
HCSEC-2024-22 - Consul L7 Intentions Vulnerable To URL Path Bypass
|
|
0
|
1549
|
October 30, 2024
|
|
HCSEC-2024-16 - Consul UI Development Workflows Vulnerable to Dependency Confusion
|
|
0
|
1029
|
July 25, 2024
|
|
HCSEC-2023-32 - Vault, Consul, and Boundary Affected By HTTP/2 “Rapid Reset” Denial of Service Vulnerability (CVE-2023-44487)
|
|
0
|
14072
|
November 2, 2023
|
|
HCSEC-2023-25 - Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
|
|
0
|
8041
|
August 8, 2023
|
|
HCSEC-2023-16 - Consul Envoy Extension Downstream Proxy Configuration By Upstream Service Owner
|
|
0
|
6283
|
June 2, 2023
|
|
HCSEC-2023-15 - Consul Cluster Peering can Result in Denial of Service
|
|
0
|
6632
|
June 2, 2023
|
|
HCSEC-2021-16 - Consul’s Application-Aware Intentions Deny Action Fails Open When Combined With Default Deny Policy
|
|
0
|
8417
|
July 15, 2021
|
|
HCSEC-2020-14 - Consul DNS and HTTP Cache Abuse Denial of Service
|
|
0
|
4308
|
November 25, 2020
|
|
HCSEC-2023-02 - Vault, Consul, Boundary, and Waypoint Affected By Denial of Service in Go’s net/http (CVE-2022-41717)
|
|
0
|
5386
|
February 8, 2023
|
|
HCSEC-2022-28 - Consul Cluster Peering Leaks Imported Nodes/Services Information
|
|
0
|
6424
|
November 15, 2022
|
|
HCSEC-2022-20 - Consul Service Mesh Intention Bypass with Malicious Certificate Signing Request
|
|
0
|
7949
|
September 21, 2022
|
|
HCSEC-2022-19 - Consul Auto-Config JWT Authorization Missing Input Validation
|
|
0
|
7333
|
September 21, 2022
|
|
HCSEC-2022-10 - Consul’s HTTP Health Check May Allow Server Side Request Forgery
|
|
0
|
11094
|
April 15, 2022
|
|
HCSEC-2022-07 - Consul’s Connect Service Mesh Affected By Recent Envoy Security Releases
|
|
0
|
4887
|
March 1, 2022
|
|
HCSEC-2022-05 - Consul Ingress Gateway Panic Can Shutdown Servers
|
|
0
|
7432
|
February 15, 2022
|
|
HCSEC-2021-34 - Vault, Consul, Boundary, and Waypoint Affected By Denial of Service in Golang’s net/http (CVE-2021-44716)
|
|
0
|
5163
|
December 22, 2021
|
|
HCSEC-2021-29 - Consul Enterprise Namespace Default ACLs Allow Privilege Escalation
|
|
0
|
8176
|
November 13, 2021
|
|
HCSEC-2021-24 - Consul Missing Authorization Check on Txn.Apply Endpoint
|
|
0
|
7850
|
September 1, 2021
|
|
HCSEC-2021-23 - Consul Exposed to Denial of Service in GoGo Protobuf Dependency
|
|
0
|
9250
|
September 1, 2021
|
|
HCSEC-2021-22 - Consul Raft RPC Privilege Escalation
|
|
0
|
9351
|
September 1, 2021
|