Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This vulnerability (CVE-2026-87106) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4. | |
| Title | Consul vulnerable to a denial of service in the native RPC listener | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-09-10T19:02:24.164Z
Reserved: 2026-09-08T20:19:26.410Z
Link: CVE-2026-87106
Updated: 2026-09-10T19:02:19.884Z
Status : Awaiting Analysis
Published: 2026-09-10T19:17:37.293
Modified: 2026-09-10T19:45:14.210
Link: CVE-2026-87106
No data.
OpenCVE Enrichment
No data.
-
CWE-400
Uncontrolled Resource Consumption