PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15972 HashiCorp CVE debrief

CVE-2026-15972 AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T20:16:50.020Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This unauthenticated denial of service vulnerability affects Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2, potentially allowing a remote attacker to exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections on external gRPC listeners. Administrators should verify deployments, apply patches in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3, and monitor for anomalies. Evidence is limited; defenders should verify Consul versions and review CVE and NVD details to assess exposure.

Vendor
HashiCorp
Product
Consul
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-08-28
Advisory published
2026-08-07
Advisory updated
2026-08-28

Who should care

Administrators and users of Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 should be aware of this vulnerability and take steps to mitigate it. This includes verifying deployments, applying patches, and monitoring for anomalies. Security teams and operators managing Consul should prioritize patching due to the HIGH CVSS score of 7.5 and potential denial of service via unbounded connection acceptance on external gRPC listeners.

Technical summary

CVE-2026-15972 is an unauthenticated denial of service vulnerability in Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections on external gRPC listeners, potentially preventing legitimate clients from connecting. This issue is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

Defensive priority

CVE-2026-15972 is rated HIGH with a CVSS score of 7.5. Consider prioritizing patching for Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 due to potential denial of service via unbounded connection acceptance on external gRPC listeners.

Recommended defensive actions

  • Inventory and verify Consul versions 1.13.0 through 2.0.2 for potential vulnerability
  • Apply patches in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3
  • Monitor gRPC listener connections for anomalies
  • Implement compensating controls to limit connection acceptance
  • Exception tracking for legitimate client connections

Evidence notes

Evidence is limited; verify Consul versions 1.13.0 through 2.0.2 for potential denial of service vulnerability via unbounded connection acceptance. Check for official patches in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. Grounding from CVE Program and NVD indicates unauthenticated denial of service through external gRPC listeners. Defenders should verify Consul deployments, review CVE and NVD details, and assess exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15972 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15972

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15972 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15972

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.