CVE-2025-11375
EUVD-2025-3656128.10.2025, 21:15
Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hashicorp | consul | 𝑥 < 1.18.12 |
| hashicorp | consul | 𝑥 < 1.22.0 |
| hashicorp | consul | 1.19.0 ≤ 𝑥 < 1.20.8 |
| hashicorp | consul | 1.21.0 ≤ 𝑥 < 1.21.6 |
𝑥
= Vulnerable software versions
Ubuntu Releases