What is CVE-2026-15972?
CVE-2026-15972 is an unauthenticated denial-of-service vulnerability in Consul Community Edition and Consul Enterprise versions 1.13.0 through 2.0.2. A remote attacker can exhaust agent file descriptors, goroutines, and memory by exploiting unbounded connection acceptance on external gRPC listeners. Mitigation involves restricting network access to these gRPC listeners.
Azərbaycanca: CVE-2026-15972, Consul Community Edition və Consul Enterprise 1.13.0-dan 2.0.2-ə qədər versiyalarda autentifikasiyasız xidmət imtinası (DoS) zəifliyidir. Xarici gRPC listener-lərdə məhdudiyyətsiz bağlantı qəbulu ilə uzaq hücumçu fayl deskriptorlarını, goroutine-ləri və yaddaşı tükəndirə bilər. Təsirə məruz qalan sistemlərdə gRPC listener-lərini şəbəkə səviyyəsində məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Consul
FAQ2
Which Consul versions are affected by CVE-2026-15972?
The vulnerability affects Consul Community Edition and Consul Enterprise versions 1.13.0 through 2.0.2.
What resources can be exhausted if CVE-2026-15972 is exploited?
Successful exploitation can exhaust agent file descriptors, goroutines, and memory, leading to a denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.