CyberRota Analysis
AI-GeneratedConsul Community Edition and Consul Enterprise versions 1.17.0 through 2.0.2 are susceptible to an uncontrolled resource consumption vulnerability in the Connect authorization endpoint, which can lead to unbounded growth of the agent's intention-match cache, bypassing the operator's cache-disable settings. This could result in degraded performance or denial of service for affected systems. Organizations using these versions should prioritize upgrading to Consul 2.0.3 or the specified Enterprise versions to mitigate this risk.
Original NVD Description
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-190124, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.