CVE-2023-1297: Hashicorp Consul

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3

Affected products

  • Hashicorp Consul: from 1.13.0, before 1.14.7 (fixed in 1.14.7); from 1.15.0, before 1.15.3 (fixed in 1.15.3)

Published 2023-06-02. Last modified 2026-06-17.