Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
History

Thu, 30 Oct 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 29 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Hashicorp
Hashicorp consul
Vendors & Products Hashicorp
Hashicorp consul

Tue, 28 Oct 2025 20:30:00 +0000

Type Values Removed Values Added
Description Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
Title Consul's event endpoint is vulnerable to denial of service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HashiCorp

Published: 2025-10-28T20:12:14.325Z

Updated: 2025-10-29T17:34:25.690Z

Reserved: 2025-10-06T15:34:11.889Z

Link: CVE-2025-11375

cve-icon Vulnrichment

Updated: 2025-10-29T17:34:21.069Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-28T21:15:37.470

Modified: 2025-10-30T15:05:32.197

Link: CVE-2025-11375

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-28T20:12:14Z

Links: CVE-2025-11375 - Bugzilla