Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
Any version before 1.22.0
affected
Default status
unaffected
Any version before 1.22.0
affected
Description
Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
Any version before 1.22.0
Any version before 1.22.0
References
discuss.hashicorp.com/...lnerable-to-denial-of-service/76723
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.