Vulnerability Description
Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Consul | < 1.18.12 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-11374?
CVE-2025-11374 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is fixed in...
How severe is CVE-2025-11374?
CVE-2025-11374 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11374?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Consul.