{"id":"CLEANSTART-2026-HZ65290","summary":"Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header","details":"Security vulnerability affects the consul package. Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header.","modified":"2026-10-02T00:45:12.304620065Z","published":"2026-10-02T00:35:54.060043Z","upstream":["CVE-2025-11375"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-HZ65290.json"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-11375"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11375"}],"affected":[{"package":{"name":"consul","ecosystem":"CleanStart"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.21.5-r4"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-HZ65290.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}