---
id: CVE-2024-10006
title: >-
  hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass
  (CVE-2024-10006)
summary: >-
  A flaw was found in HashiCorp Consul and Consul Enterprise. The server
  response does not explicitly set a Content-Type HTTP header, allowing
  user-provided inputs to be misinterpreted and can lead to reflected cross-site
  scripting (XSS).
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'
cvssSource: vendor
cwe: CWE-644
vendor: Red Hat
product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.23
affected:
  - openshift_dev_spaces_rhosds 3.23
patched:
  - openshift_dev_spaces_rhosds 3.23
published: '2024-10-30'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T15:04:25+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-10006.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-10006.json
  - url: 'https://access.redhat.com/security/cve/CVE-2024-10006'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2322858'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-10006'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-10006'
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2024-23-consul-l7-intentions-vulnerable-to-headers-bypass
  - url: 'https://access.redhat.com/errata/RHSA-2025:15847'
  - url: 'https://github.com/hashicorp/consul/pull/21816'
  - url: >-
      https://github.com/hashicorp/consul/commit/d9206fc7e284a9244af4d62f8653a63ca30bd00c
  - url: 'https://github.com/hashicorp/consul'
  - url: 'https://security.netapp.com/advisory/ntap-20250110-0005'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00467
epssPercentile: 0.37824
aliases:
  - GHSA-5c4w-8hhh-3c3h
  - BIT-consul-2024-10006
  - GO-2024-3241
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.755Z'
---

## Overview

A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).

## Vendor advisories

- **RHSA-2025:15847** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces (RHOSDS) 3.23 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15847)

**hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass** — rated Important by Red Hat. Released 2024-10-30, updated 2026-09-21.

Fixed:

- Red Hat OpenShift Dev Spaces (RHOSDS) 3.23

Not affected:

- Red Hat OpenShift Dev Spaces (RHOSDS) 3.23

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15847

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2024-10006)

Affected packages:

- `github.com/hashicorp/consul >= 1.9.0, < 1.20.1`

Patched in:

- `github.com/hashicorp/consul 1.20.1`

Source: https://osv.dev/vulnerability/GHSA-5c4w-8hhh-3c3h
