Consul

Vendor:

First CVE: Dec 9, 2018 · Active for 7 years

35
Total CVEs
More Total CVEs than 96% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Consul over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2018
7 years ago
Most Recent CVE
Oct 28, 2025
270 days ago

CVE Severity & Scoring

Consul35 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network35 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (88.6%)
High4 (11.4%)
Unknown0 (0.0%)
User Interaction
None33 (94.3%)
Unknown0 (0.0%)
Required2 (5.7%)
Privileges Required
Low11 (31.4%)
High0 (0.0%)
None24 (68.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in
Dec 12, 20218.847NONO
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health
Apr 19, 20227.539NOYES
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.
Apr 20, 20216.131NOYES
An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.
Jan 11, 20218.629NONO
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling p
Sep 7, 20218.827NONO
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incor
Jul 17, 20217.525NONO
HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fi
Jul 17, 20217.525NONO
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.
Nov 4, 20207.525NONO
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto co
Sep 23, 20227.124NONO
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.
Apr 20, 20217.524NONO

Exploit Exposure

Signals from CVEs in this product scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (35 CVEs).

Media Mentions

Signals from CVEs in this product scope (35 CVEs).

Top CNAs Publishing CVEs For Consul

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.4.317.40.6%00
1.20.025.80.6%00
1.16.017.30.4%00
1.13.117.10.9%00
1.12.417.10.9%00
1.1.018.10.7%00