{"id":"CVE-2020-7219","aliases":["GHSA-23jv-v6qj-3fhh","BIT-consul-2020-7219","GO-2022-0776"],"title":"Denial of Service (DoS) in HashiCorp Consul","summary":"Denial of Service (DoS) in HashiCorp Consul","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"hashicorp","product":"github.com/hashicorp/consul","ecosystem":"go","affected":["github.com/hashicorp/consul < 1.6.3"],"patched":["github.com/hashicorp/consul 1.6.3"],"published":"2021-05-18","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:26.885066499Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-23jv-v6qj-3fhh","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7219"},{"url":"https://github.com/hashicorp/consul/issues/7159"},{"url":"https://www.hashicorp.com/blog/category/consul"}],"tags":["osv","go"],"epss":0.0201,"epssPercentile":0.79736,"ingestedAt":"2026-09-12T03:13:01.744Z","slug":"CVE-2020-7219","body":"## Overview\n\nHashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.\n\n### Specific Go Packages Affected\ngithub.com/hashicorp/consul/agent/consul\n\n## Affected packages\n\n- `github.com/hashicorp/consul < 1.6.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/hashicorp/consul 1.6.3`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}