CVE-2021-41803High· 7.1▾ TwilightHashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
0.9% → 1.1%
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 did not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2.
github.com/hashicorp/consul >= 1.8.1, < 1.11.9github.com/hashicorp/consul >= 1.12.0, < 1.12.5github.com/hashicorp/consul >= 1.13.0, < 1.13.2Upgrade to a patched release:
github.com/hashicorp/consul 1.11.9github.com/hashicorp/consul 1.12.5github.com/hashicorp/consul 1.13.2Connected by shared product, vendor, weakness, or advisory.
CVE-2023-0845Medium· 6.5Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
CVE-2025-11374Medium· 6.5Consul key/value endpoint is vulnerable to denial of service
CVE-2021-38698Medium· 6.5HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…
CVE-2018-19653Medium· 5.9HashiCorp Consul can use cleartext agent-to-agent RPC communication
CVE-2023-3518High· 7.4Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
CVE-2020-7219High· 7.5Denial of Service (DoS) in HashiCorp Consul