CVE-2024-10006High· 8.3▾ TwilightA flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
0.5% → 0.5%
Last analysed / modified upstream
A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).
hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass — rated Important by Red Hat. Released 2024-10-30, updated 2026-09-21.
Fixed:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15847
Workarounds / mitigations:
Affected packages:
github.com/hashicorp/consul >= 1.9.0, < 1.20.1Patched in:
github.com/hashicorp/consul 1.20.1Connected by shared product, vendor, weakness, or advisory.
CVE-2024-28869High· 7.5traefik: denial of service (CVE-2024-28869)
CVE-2026-93433Medium· 5.5A flaw was found in libstoragemgmt
CVE-2026-92382Medium· 4.1An out-of-bounds write flaw was found in usbredir
CVE-2026-94449High· 7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror