Consul
Vendor:
First CVE: Dec 9, 2018 · Active for 7 years
35
Total CVEs
More Total CVEs than 96% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Consul over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2018
7 years ago
Most Recent CVE
Oct 28, 2025
270 days ago
CVE Severity & Scoring
Consul35 CVEs
43%
57%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network35 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (88.6%)
High4 (11.4%)
Unknown0 (0.0%)
User Interaction
None33 (94.3%)
Unknown0 (0.0%)
Required2 (5.7%)
Privileges Required
Low11 (31.4%)
High0 (0.0%)
None24 (68.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41805HIGH HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in | Dec 12, 2021 | 8.8 | 47 | NO | NO |
CVE-2022-29153HIGH HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health | Apr 19, 2022 | 7.5 | 39 | NO | YES |
CVE-2020-25864MEDIUM HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14. | Apr 20, 2021 | 6.1 | 31 | NO | YES |
CVE-2021-3121HIGH An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue. | Jan 11, 2021 | 8.6 | 29 | NO | NO |
CVE-2021-37219HIGH HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling p | Sep 7, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-36213HIGH HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incor | Jul 17, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-32574HIGH HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fi | Jul 17, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-25201HIGH HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7. | Nov 4, 2020 | 7.5 | 25 | NO | NO |
CVE-2021-41803HIGH HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto co | Sep 23, 2022 | 7.1 | 24 | NO | NO |
CVE-2021-28156HIGH HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10. | Apr 20, 2021 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Consul
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.4.3 | 1 | 7.4 | 0.6% | 0 | 0 |
| 1.20.0 | 2 | 5.8 | 0.6% | 0 | 0 |
| 1.16.0 | 1 | 7.3 | 0.4% | 0 | 0 |
| 1.13.1 | 1 | 7.1 | 0.9% | 0 | 0 |
| 1.12.4 | 1 | 7.1 | 0.9% | 0 | 0 |
| 1.1.0 | 1 | 8.1 | 0.7% | 0 | 0 |