Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7g3r-8c6v-hfmr | Consul key/value endpoint is vulnerable to denial of service |
Mon, 22 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* |
Thu, 30 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 29 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp consul |
|
| Vendors & Products |
Hashicorp
Hashicorp consul |
Tue, 28 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12. | |
| Title | Consul's KV endpoint is vulnerable to denial of service | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-04-17T18:34:14.829Z
Reserved: 2025-10-06T15:34:09.965Z
Link: CVE-2025-11374
Updated: 2025-10-28T20:36:00.377Z
Status : Analyzed
Published: 2025-10-28T21:15:37.300
Modified: 2025-12-22T16:05:52.177
Link: CVE-2025-11374
OpenCVE Enrichment
Updated: 2026-04-20T16:00:10Z
Github GHSA