CVE-2026-87106
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in Consul via RPC Memory Exhaustion

Vulnerability report for CVE-2026-87106, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: HashiCorp Inc.

Description

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This vulnerability (CVE-2026-87106) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
hashicorp consul to 2.0.4 (inc)
hashicorp consul_enterprise to 1.21.18 (inc)
hashicorp consul_enterprise to 1.22.12 (inc)
hashicorp consul_enterprise to 2.0.4 (inc)
hashicorp consul From 1.21.0 (inc) to 2.0.4 (exc)
hashicorp consul_enterprise 1.21.18
hashicorp consul_enterprise 1.22.12
hashicorp consul_enterprise From 1.21.0 (inc) to 2.0.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener. An authenticated client can send a specially crafted request that exhausts server memory before ACL authorization is evaluated. This may cause process termination and disrupt control-plane operations. The issue requires reaching the server RPC listener and completing the mTLS handshake but does not need a valid ACL token.

Detection Guidance

Monitor Consul server memory usage and RPC listener logs for unusual activity. Check for clients completing mTLS handshakes without valid ACL tokens. Use Consul's built-in metrics endpoint to track memory exhaustion patterns.

Impact Analysis

This vulnerability can cause denial of service by exhausting server memory, leading to process termination and disruption of control-plane operations. It may impact availability of Consul services and require upgrading to patched versions to mitigate risks.

Mitigation Strategies

Upgrade Consul to version 2.0.4 or Consul Enterprise to 1.21.18, 1.22.12, or 2.0.4 immediately. Restrict network access to the RPC listener port to trusted clients only. Review and enforce ACL policies to limit client access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87106. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart