CVE-2025-11374
Consul's KV endpoint is vulnerable to denial of service
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
9th
Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
| CWE | CWE-770 |
| Vendor | hashicorp |
| Product | consul |
| Published | Oct 28, 2025 |
| Last Updated | Apr 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for hashicorp consul
Be the first to know when new medium vulnerabilities affecting hashicorp consul are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
HashiCorp / Consul
0 < 1.22.0
HashiCorp / Consul Enterprise
0 < 1.22.0
References
Credits
This issue was identified by Julien Ahrens from RCE Security ([https://www.rcesecurity.com/|https://www.rcesecurity.com/|smart-link] ).