---
id: CVE-2025-11374
title: >-
  github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of
  service (CVE-2025-11374)
summary: >-
  A denial of service flaw has been discovered in Hashicorp Consul. The
  key/value endpoint is vulnerable to denial of service (DoS) due to incorrect
  Content Length header validation.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-770
vendor: Red Hat
product: Red Hat OpenShift Dev Spaces
affected:
  - openshift_dev_spaces
patched:
  - github.com/hashicorp/consul 1.22.0
published: '2025-10-28'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T03:37:23+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11374.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11374.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-11374'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2406934'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-11374'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11374'
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2025-29-consuls-kv-endpoint-is-vulnerable-to-denial-of-service/76724
  - url: 'https://github.com/hashicorp/consul/pull/22916'
  - url: >-
      https://github.com/hashicorp/consul/commit/72a358cd02533477536ad4bd2b781f520fa7fac6
  - url: 'https://github.com/hashicorp/consul'
  - url: 'https://github.com/hashicorp/consul/releases/tag/v1.22.0'
  - url: 'https://pkg.go.dev/vuln/GO-2025-4081'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00396
epssPercentile: 0.31115
aliases:
  - GHSA-7g3r-8c6v-hfmr
  - BIT-consul-2025-11374
  - GO-2025-4081
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.764Z'
---

## Overview

A denial of service flaw has been discovered in Hashicorp Consul. The key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift Dev Spaces · no fix planned: Red Hat OpenShift Dev Spaces · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11374.json)

**github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service** — rated Moderate by Red Hat. Released 2025-10-28, updated 2026-09-23.

Affected:

- Red Hat OpenShift Dev Spaces

No fix planned:

- Red Hat OpenShift Dev Spaces

## Remediation

Fix deferred

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-11374)

Affected packages:

- `github.com/hashicorp/consul < 1.22.0`

Patched in:

- `github.com/hashicorp/consul 1.22.0`

Source: https://osv.dev/vulnerability/GHSA-7g3r-8c6v-hfmr
