PatchSiren cyber security CVE debrief
CVE-2026-15972 HashiCorp CVE debrief
CVE-2026-15972 AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T20:16:50.020Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This unauthenticated denial of service vulnerability affects Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2, potentially allowing a remote attacker to exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections on external gRPC listeners. Administrators should verify deployments, apply patches in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3, and monitor for anomalies. Evidence is limited; defenders should verify Consul versions and review CVE and NVD details to assess exposure.
- Vendor
- HashiCorp
- Product
- Consul
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-08-28
Who should care
Administrators and users of Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 should be aware of this vulnerability and take steps to mitigate it. This includes verifying deployments, applying patches, and monitoring for anomalies. Security teams and operators managing Consul should prioritize patching due to the HIGH CVSS score of 7.5 and potential denial of service via unbounded connection acceptance on external gRPC listeners.
Technical summary
CVE-2026-15972 is an unauthenticated denial of service vulnerability in Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections on external gRPC listeners, potentially preventing legitimate clients from connecting. This issue is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Defensive priority
CVE-2026-15972 is rated HIGH with a CVSS score of 7.5. Consider prioritizing patching for Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 due to potential denial of service via unbounded connection acceptance on external gRPC listeners.
Recommended defensive actions
- Inventory and verify Consul versions 1.13.0 through 2.0.2 for potential vulnerability
- Apply patches in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3
- Monitor gRPC listener connections for anomalies
- Implement compensating controls to limit connection acceptance
- Exception tracking for legitimate client connections
Evidence notes
Evidence is limited; verify Consul versions 1.13.0 through 2.0.2 for potential denial of service vulnerability via unbounded connection acceptance. Check for official patches in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. Grounding from CVE Program and NVD indicates unauthenticated denial of service through external gRPC listeners. Defenders should verify Consul deployments, review CVE and NVD details, and assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15972 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15972
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15972 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15972
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.hashicorp.com/t/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul/77629
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.