CyberRota Analysis
AI-GeneratedConsul Community Edition and Consul Enterprise versions 1.2.0 through 2.0.2 are susceptible to an uncontrolled resource consumption vulnerability in the Connect CA roots endpoint, which can allow remote attackers to exhaust the agent's cache resources, bypassing cache-disable settings. This could lead to performance degradation or service disruption. Organizations using affected versions should prioritize upgrading to Consul 2.0.3 or the specified Enterprise versions to mitigate potential risks.
Original NVD Description
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.