What is CVE-2026-19015?
CVE-2026-19015 is an uncontrolled resource consumption vulnerability in the Connect CA roots endpoint of Consul Community Edition and Consul Enterprise versions 1.2.0 through 2.0.2. It allows a remote caller to indefinitely grow the agent's Connect CA roots cache, bypassing the cache-disable configuration. Affected systems should be updated to the latest version.
Azərbaycanca: CVE-2026-19015, Consul Community Edition və Consul Enterprise 1.2.0-dən 2.0.2-yə qədər versiyalarda Connect CA roots endpoint-də nəzarətsiz resurs istehlakı (Uncontrolled Resource Consumption) zəifliyidir. Bu, uzaqdan edilən sorğularla agentin Connect CA kök sertifikat keşini limitsiz böyüdərək cache-disable konfiqurasiyasını sıradan çıxara bilər. Təsirə məruz qalan sistemlərin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Consul
FAQ2
In which product was the CVE-2026-19015 vulnerability discovered in the Connect CA roots endpoint?
This vulnerability was discovered in Consul Community Edition and Consul Enterprise.
What configuration can a remote attacker bypass by exploiting CVE-2026-19015?
By exploiting this vulnerability, a remote caller can indefinitely grow the agent's Connect CA roots cache, bypassing the cache-disable configuration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.