CVE-2020-25201: Hashicorp Consul

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.

Affected products

  • Hashicorp Consul: from 1.7.0, up to and including 1.8.4

Published 2020-11-04. Last modified 2026-06-17.