{"schema_version":1,"title":"github.com/hashicorp/consul (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in github.com/hashicorp/consul (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-2808, was published on 16 March 2026.","url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-consul","json_url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-consul.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-hashicorp-consul","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":32,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":3},"latest":[{"cve":"CVE-2026-2808","cvss":3.1,"epss":0.0055,"slug":"cve-2026-2808-consul-is-vulnerable-to-arbitrary-file-read-when-configured-with","title":"GO-2026-4690 - Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2026-03-16T18:33:12+00:00","url":"https://junglewise.ai/threats/cve-2026-2808-consul-is-vulnerable-to-arbitrary-file-read-when-configured-with"},{"cve":"CVE-2025-11375","cvss":3.1,"epss":0.004,"slug":"cve-2025-11375-consul-event-endpoint-is-vulnerable-to-denial-of-service","title":"GO-2025-4082 - Consul event endpoint is vulnerable to denial of service in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:15+00:00","url":"https://junglewise.ai/threats/cve-2025-11375-consul-event-endpoint-is-vulnerable-to-denial-of-service"},{"cve":"CVE-2025-11374","cvss":3.1,"epss":0.004,"slug":"cve-2025-11374-consul-key-value-endpoint-is-vulnerable-to-denial-of-service","title":"GO-2025-4081 - Consul key/value endpoint is vulnerable to denial of service in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:15+00:00","url":"https://junglewise.ai/threats/cve-2025-11374-consul-key-value-endpoint-is-vulnerable-to-denial-of-service"},{"cve":"CVE-2024-10006","cvss":3.1,"epss":0.0047,"slug":"cve-2024-10006-hashicorp-consul-improper-neutralization-of-http-headers-for","title":"GO-2024-3241 - Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-11-04T15:44:16+00:00","url":"https://junglewise.ai/threats/cve-2024-10006-hashicorp-consul-improper-neutralization-of-http-headers-for"},{"cve":"CVE-2024-10086","cvss":3.1,"epss":0.0042,"slug":"cve-2024-10086-hashicorp-consul-cross-site-scripting-vulnerability","title":"GO-2024-3242 - Hashicorp Consul Cross-site Scripting vulnerability in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-11-04T15:44:16+00:00","url":"https://junglewise.ai/threats/cve-2024-10086-hashicorp-consul-cross-site-scripting-vulnerability"},{"cve":"CVE-2024-10005","cvss":3.1,"epss":0.0077,"slug":"cve-2024-10005-hashicorp-consul-path-traversal-vulnerability","title":"GO-2024-3243 - Hashicorp Consul Path Traversal vulnerability in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-11-04T15:44:16+00:00","url":"https://junglewise.ai/threats/cve-2024-10005-hashicorp-consul-path-traversal-vulnerability"},{"cve":"CVE-2022-3920","cvss":3.1,"epss":0.007,"slug":"cve-2022-3920-missing-authorization-in-hashicorp-consul","title":"GO-2022-1121 - Missing Authorization in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T16:03:26+00:00","url":"https://junglewise.ai/threats/cve-2022-3920-missing-authorization-in-hashicorp-consul"},{"cve":"CVE-2022-40716","cvss":3.1,"epss":0.0108,"slug":"cve-2022-40716-hashicorp-consul-vulnerable-to-authorization-bypass","title":"GO-2022-1029 - HashiCorp Consul vulnerable to authorization bypass in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T16:03:24+00:00","url":"https://junglewise.ai/threats/cve-2022-40716-hashicorp-consul-vulnerable-to-authorization-bypass"},{"cve":"CVE-2022-24687","cvss":3.1,"epss":0.0149,"slug":"cve-2022-24687-hashicorp-consul-ingress-gateway-panic-can-shutdown-servers","title":"GO-2022-0953 - HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T16:03:21+00:00","url":"https://junglewise.ai/threats/cve-2022-24687-hashicorp-consul-ingress-gateway-panic-can-shutdown-servers"},{"cve":"CVE-2021-36213","cvss":3.1,"epss":0.0169,"slug":"cve-2021-36213-hashicorp-consul-l7-deny-intention-results-in-an-allow-action","title":"GO-2022-0895 - HashiCorp Consul L7 deny intention results in an allow action in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-36213-hashicorp-consul-l7-deny-intention-results-in-an-allow-action"},{"cve":"CVE-2021-32574","cvss":3.1,"epss":0.0146,"slug":"cve-2021-32574-hashicorp-consul-missing-ssl-certificate-validation","title":"GO-2022-0894 - Hashicorp Consul Missing SSL Certificate Validation in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-32574-hashicorp-consul-missing-ssl-certificate-validation"},{"cve":"CVE-2020-13250","cvss":3.1,"epss":0.0285,"slug":"cve-2020-13250-allocation-of-resources-without-limits-or-throttling-in-hashicorp","title":"GO-2022-0879 - Allocation of Resources Without Limits or Throttling in Hashicorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-13250-allocation-of-resources-without-limits-or-throttling-in-hashicorp"},{"cve":"CVE-2020-13170","cvss":3.1,"epss":0.0173,"slug":"cve-2020-13170-improper-input-validation-in-hashicorp-consul","title":"GO-2022-0859 - Improper Input Validation in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-13170-improper-input-validation-in-hashicorp-consul"},{"cve":"CVE-2020-12758","cvss":3.1,"epss":0.0171,"slug":"cve-2020-12758-denial-of-service-dos-in-hashicorp-consul","title":"GO-2022-0861 - Denial of Service (DoS) in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-12758-denial-of-service-dos-in-hashicorp-consul"},{"cve":"CVE-2020-7955","cvss":3.1,"epss":0.0141,"slug":"cve-2020-7955-incorrect-authorization-in-hashicorp-consul","title":"GO-2022-0874 - Incorrect Authorization in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-7955-incorrect-authorization-in-hashicorp-consul"},{"cve":"CVE-2020-12797","cvss":3.1,"epss":0.0155,"slug":"cve-2020-12797-incorrect-permission-assignment-for-critical-resource-in","title":"GO-2022-0847 - Incorrect Permission Assignment for Critical Resource in Hashicorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:04+00:00","url":"https://junglewise.ai/threats/cve-2020-12797-incorrect-permission-assignment-for-critical-resource-in"},{"cve":"CVE-2020-7219","cvss":3.1,"epss":0.0201,"slug":"cve-2020-7219-denial-of-service-dos-in-hashicorp-consul","title":"GO-2022-0776 - Denial of Service (DoS) in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:28:59+00:00","url":"https://junglewise.ai/threats/cve-2020-7219-denial-of-service-dos-in-hashicorp-consul"},{"cve":"CVE-2022-29153","cvss":3.1,"epss":0.0868,"slug":"cve-2022-29153-hashicorp-consul-http-health-check-endpoints-returning-an-http","title":"GO-2022-0615 - Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2022-29153-hashicorp-consul-http-health-check-endpoints-returning-an-http"},{"cve":"CVE-2021-37219","cvss":3.1,"epss":0.0115,"slug":"cve-2021-37219-hashicorp-consul-privilege-escalation-vulnerability","title":"GO-2022-0593 - HashiCorp Consul Privilege Escalation Vulnerability in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:38+00:00","url":"https://junglewise.ai/threats/cve-2021-37219-hashicorp-consul-privilege-escalation-vulnerability"},{"cve":"CVE-2021-38698","cvss":3.1,"epss":0.0142,"slug":"cve-2021-38698-hashicorp-consul-and-consul-enterprise-1-10-1-txn-apply-endpoint","title":"GO-2022-0559 - HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:36+00:00","url":"https://junglewise.ai/threats/cve-2021-38698-hashicorp-consul-and-consul-enterprise-1-10-1-txn-apply-endpoint"},{"cve":"CVE-2019-8336","cvss":3,"epss":0.0125,"slug":"cve-2019-8336-hashicorp-consul-access-restriction-bypass","title":"GO-2023-1945 - HashiCorp Consul Access Restriction Bypass in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-20T20:31:38+00:00","url":"https://junglewise.ai/threats/cve-2019-8336-hashicorp-consul-access-restriction-bypass"},{"cve":"CVE-2019-9764","cvss":3,"epss":0.0061,"slug":"cve-2019-9764-hashicorp-consul-vulnerable-to-origin-validation-error","title":"GO-2023-1853 - HashiCorp Consul vulnerable to Origin Validation Error in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-20T20:31:32+00:00","url":"https://junglewise.ai/threats/cve-2019-9764-hashicorp-consul-vulnerable-to-origin-validation-error"},{"cve":"CVE-2018-19653","cvss":3,"epss":0.0122,"slug":"cve-2018-19653-hashicorp-consul-can-use-cleartext-agent-to-agent-rpc","title":"GO-2023-1850 - HashiCorp Consul can use cleartext agent-to-agent RPC communication in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-20T20:31:32+00:00","url":"https://junglewise.ai/threats/cve-2018-19653-hashicorp-consul-can-use-cleartext-agent-to-agent-rpc"},{"cve":"CVE-2020-25864","cvss":3.1,"epss":0.0607,"slug":"cve-2020-25864-hashicorp-consul-cross-site-scripting-vulnerability","title":"GO-2023-1851 - HashiCorp Consul Cross-site Scripting vulnerability in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-20T20:31:32+00:00","url":"https://junglewise.ai/threats/cve-2020-25864-hashicorp-consul-cross-site-scripting-vulnerability"},{"cve":"CVE-2019-12291","cvss":3,"epss":0.0116,"slug":"cve-2019-12291-hashicorp-consul-incorrect-access-control-vulnerability","title":"GO-2023-1852 - HashiCorp Consul Incorrect Access Control vulnerability in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-20T20:31:32+00:00","url":"https://junglewise.ai/threats/cve-2019-12291-hashicorp-consul-incorrect-access-control-vulnerability"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vulnerabilities":188,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"stdlib (Go)","slug":"go-stdlib","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/go-stdlib"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"}],"technology":{"hub":true,"name":"github.com/hashicorp/consul (Go)","slug":"github-com-hashicorp-consul","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-consul"},"most_severe":[{"cve":"CVE-2022-29153","cvss":3.1,"epss":0.0868,"slug":"cve-2022-29153-hashicorp-consul-http-health-check-endpoints-returning-an-http","title":"GO-2022-0615 - Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2022-29153-hashicorp-consul-http-health-check-endpoints-returning-an-http"},{"cve":"CVE-2020-25864","cvss":3.1,"epss":0.0607,"slug":"cve-2020-25864-hashicorp-consul-cross-site-scripting-vulnerability","title":"GO-2023-1851 - HashiCorp Consul Cross-site Scripting vulnerability in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-20T20:31:32+00:00","url":"https://junglewise.ai/threats/cve-2020-25864-hashicorp-consul-cross-site-scripting-vulnerability"},{"cve":"CVE-2020-13250","cvss":3.1,"epss":0.0285,"slug":"cve-2020-13250-allocation-of-resources-without-limits-or-throttling-in-hashicorp","title":"GO-2022-0879 - Allocation of Resources Without Limits or Throttling in Hashicorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-13250-allocation-of-resources-without-limits-or-throttling-in-hashicorp"},{"cve":"CVE-2020-25201","cvss":3.1,"epss":0.0261,"slug":"cve-2020-25201-denial-of-service-in-hashicorp-consul","title":"GO-2024-2501 - Denial of service in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2020-25201-denial-of-service-in-hashicorp-consul"},{"cve":"CVE-2020-7219","cvss":3.1,"epss":0.0201,"slug":"cve-2020-7219-denial-of-service-dos-in-hashicorp-consul","title":"GO-2022-0776 - Denial of Service (DoS) in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:28:59+00:00","url":"https://junglewise.ai/threats/cve-2020-7219-denial-of-service-dos-in-hashicorp-consul"},{"cve":"CVE-2020-13170","cvss":3.1,"epss":0.0173,"slug":"cve-2020-13170-improper-input-validation-in-hashicorp-consul","title":"GO-2022-0859 - Improper Input Validation in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-13170-improper-input-validation-in-hashicorp-consul"},{"cve":"CVE-2020-12758","cvss":3.1,"epss":0.0171,"slug":"cve-2020-12758-denial-of-service-dos-in-hashicorp-consul","title":"GO-2022-0861 - Denial of Service (DoS) in HashiCorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-12758-denial-of-service-dos-in-hashicorp-consul"},{"cve":"CVE-2021-36213","cvss":3.1,"epss":0.0169,"slug":"cve-2021-36213-hashicorp-consul-l7-deny-intention-results-in-an-allow-action","title":"GO-2022-0895 - HashiCorp Consul L7 deny intention results in an allow action in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-36213-hashicorp-consul-l7-deny-intention-results-in-an-allow-action"},{"cve":"CVE-2020-12797","cvss":3.1,"epss":0.0155,"slug":"cve-2020-12797-incorrect-permission-assignment-for-critical-resource-in","title":"GO-2022-0847 - Incorrect Permission Assignment for Critical Resource in Hashicorp Consul in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:04+00:00","url":"https://junglewise.ai/threats/cve-2020-12797-incorrect-permission-assignment-for-critical-resource-in"},{"cve":"CVE-2022-24687","cvss":3.1,"epss":0.0149,"slug":"cve-2022-24687-hashicorp-consul-ingress-gateway-panic-can-shutdown-servers","title":"GO-2022-0953 - HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers in github.com/hashicorp/consul","severity":"low","exploited":false,"published_at":"2024-08-21T16:03:21+00:00","url":"https://junglewise.ai/threats/cve-2022-24687-hashicorp-consul-ingress-gateway-panic-can-shutdown-servers"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}