{"id":"CVE-2025-11374","title":"github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service (CVE-2025-11374)","summary":"A denial of service flaw has been discovered in Hashicorp Consul. The key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-770","vendor":"Red Hat","product":"Red Hat OpenShift Dev Spaces","affected":["openshift_dev_spaces"],"patched":["github.com/hashicorp/consul 1.22.0"],"published":"2025-10-28","updated":"2026-09-23","sourceUpdated":"2026-09-23T03:37:23+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11374.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11374.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-11374"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2406934"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-11374"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11374"},{"url":"https://discuss.hashicorp.com/t/hcsec-2025-29-consuls-kv-endpoint-is-vulnerable-to-denial-of-service/76724"},{"url":"https://github.com/hashicorp/consul/pull/22916"},{"url":"https://github.com/hashicorp/consul/commit/72a358cd02533477536ad4bd2b781f520fa7fac6"},{"url":"https://github.com/hashicorp/consul"},{"url":"https://github.com/hashicorp/consul/releases/tag/v1.22.0"},{"url":"https://pkg.go.dev/vuln/GO-2025-4081"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00396,"epssPercentile":0.33673,"aliases":["GHSA-7g3r-8c6v-hfmr","BIT-consul-2025-11374","GO-2025-4081"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.764Z","slug":"CVE-2025-11374","body":"## Overview\n\nA denial of service flaw has been discovered in Hashicorp Consul. The key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift Dev Spaces · no fix planned: Red Hat OpenShift Dev Spaces · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11374.json)\n\n**github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service** — rated Moderate by Red Hat. Released 2025-10-28, updated 2026-09-23.\n\nAffected:\n\n- Red Hat OpenShift Dev Spaces\n\nNo fix planned:\n\n- Red Hat OpenShift Dev Spaces\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2025-11374)\n\nAffected packages:\n\n- `github.com/hashicorp/consul < 1.22.0`\n\nPatched in:\n\n- `github.com/hashicorp/consul 1.22.0`\n\nSource: https://osv.dev/vulnerability/GHSA-7g3r-8c6v-hfmr","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}