{"id":"CVE-2026-87106","title":"Consul vulnerable to a denial of service in the native RPC listener","summary":"Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"cna","cwe":["CWE-400"],"vendor":"HashiCorp","product":"Consul","affected":["Consul >= 1.21.0 < 2.0.4","consul_enterprise >= 1.21.0 < 2.0.4"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T19:02:15.913180Z"},"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T19:02:24.164Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-87106","references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-35-consul-vulnerable-to-a-denial-of-service-in-the-native-rpc-listener/77737"}],"tags":["cve.org"],"epss":0.00411,"epssPercentile":0.32545,"ingestedAt":"2026-09-11T16:45:48.025Z","slug":"CVE-2026-87106","body":"## Overview\n\nConsul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This vulnerability (CVE-2026-87106) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4.\n\n## Affected\n\n- `Consul >= 1.21.0 < 2.0.4`\n- `consul_enterprise >= 1.21.0 < 2.0.4`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}