CVE-2026-19015
Last modified
CVE-2026-19015 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| HashiCorp | Consul | >= 1.2.0, < 2.0.3 |
| HashiCorp | Consul Enterprise | >= 1.2.0, < 2.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-19015?
How severe is CVE-2026-19015?
How do I fix CVE-2026-19015?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19009A weakness has been identified in TinyAGI 0.0.20. This issue…7.3
- CVE-2026-1901The QuestionPro Surveys plugin for WordPress is vulnerable t…6.4
- CVE-2026-19010A security vulnerability has been detected in TinyAGI 0.0.20…7.3
- CVE-2026-19011A vulnerability was detected in TinyAGI 0.0.20. The affected…5.5
- CVE-2026-19012Consul Community Edition and Consul Enterprise 1.18.0 throug…5.3
- CVE-2026-19014Consul Community Edition and Consul Enterprise 1.17.0 throug…4.3
- CVE-2026-19016Consul Community Edition and Consul Enterprise 1.19.1 throug…4.2
- CVE-2026-19017Consul Community Edition and Consul Enterprise 1.18.21 throu…6.8
- CVE-2026-19019A security flaw has been discovered in poco-ai poco-agent up…4.8
- CVE-2026-1902The Hammas Calendar plugin for WordPress is vulnerable to St…6.4
- CVE-2026-19020A weakness has been identified in itsourcecode Hospital Mana…6.3
- CVE-2026-19021A security vulnerability has been detected in SourceCodester…7.3
Are you affected by CVE-2026-19015?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
