CVE-2026-19012
Received Received - Intake

Authenticated Denial of Service in Consul

Vulnerability report for CVE-2026-19012, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: HashiCorp Inc.

Description

Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul server. A caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This vulnerability, CVE-2026-19012, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-08
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
hashicorp consul 1.18.0
hashicorp consul 2.0.2
hashicorp consul 2.0.3
hashicorp consul 1.21.17
hashicorp consul 1.22.11

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19012 is an authenticated denial of service vulnerability in HashiCorp Consul affecting versions 1.18.0 through 2.0.2. It occurs during the Enterprise-to-Community Edition downgrade process when a compatibility check fails to handle certain service-router configuration entries, causing the Consul agent to crash.

Detection Guidance

To detect this vulnerability, check if your Consul server is running a vulnerable version (1.18.0 to 2.0.2) and if the Enterprise-to-Community Edition downgrade mode is enabled. Inspect logs for unexpected agent exits during configuration changes.

Impact Analysis

This vulnerability allows an authenticated attacker with config-entry write permission to crash the Consul server, leading to service disruption. Downtime may occur if the server exits unexpectedly, affecting availability of the Consul service.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is an authenticated denial of service issue in Consul that could disrupt service availability but does not involve unauthorized data access, processing violations, or confidentiality breaches. Compliance impact would depend on secondary effects like downtime or service disruption rather than the vulnerability itself.

Mitigation Strategies

Upgrade to a patched version: Consul Community Edition 2.0.3 or Consul Enterprise 2.0.3, 1.22.11, or 1.21.17. If downgrade mode is not needed, disable it to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19012. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart