Networking
Consul: what changed
In the last 90 days, 20 summarized changes: 20 releases. Stackdiff reads Consul's own feeds (developer.hashicorp.com) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .
Latest changes
Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.
1.22.0Securitymedium
GHSA-qh7p-pfq3-677h: Consul event endpoint is vulnerable to denial of service
1.22.0Securitymedium
GHSA-7g3r-8c6v-hfmr: Consul key/value endpoint is vulnerable to denial of service
1.20.0Securitymedium
GHSA-99wr-c2px-grmh: Hashicorp Consul Cross-site Scripting vulnerability
1.20.1Securitymedium
GHSA-5c4w-8hhh-3c3h: Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability
1.20.1Securityhigh
GHSA-chgm-7r52-whjj: Hashicorp Consul Path Traversal vulnerability
1.14.5Securitymedium
GHSA-c57c-7hrj-6q6v: Hashicorp Consul vulnerable to denial of service
1.11.9Securitymedium
GHSA-m69r-9g56-7mv8: HashiCorp Consul vulnerable to authorization bypass
1.7.14Securitymedium
GHSA-8xmx-h8rq-h94j: HashiCorp Consul Cross-site Scripting vulnerability
1.4.1Securitymedium
GHSA-4qvx-qq5w-695p: HashiCorp Consul can use cleartext agent-to-agent RPC communication
1.4.4Securityhigh
GHSA-q7fx-wm2p-qfj8: HashiCorp Consul vulnerable to Origin Validation Error
Where Stackdiff reads Consul
- endoflife.date
- Hacker News
- HashiCorp Releases API · consul
- OSV advisories · github.com/hashicorp/consul
Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.
Get Consul changes in your Monday brief
Add Consul and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.
Get your first brief →