PT-2026-94383 · Hashicorp+1 · Hashicorp Consul+1

·

CVE-2026-81516

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Steeltoe versions 4.0.0 through 4.2.9
Description The ConsulDiscoveryClient parses the secure metadata field of registered service instances using a strict Boolean conversion. If a principal registers a service with a secure value other than true or false (such as yes or 1), the resulting exception aborts the construction of the entire instance list, rendering the targeted service undiscoverable. Furthermore, when the GetAllInstancesAsync() function is used to enumerate all services, a single malformed instance can abort the enumeration process across every service. This condition is more likely to occur in mixed-platform environments where non-.NET clients register services with non-standard metadata values. The outage persists until the offending registration is removed.
Recommendations Update to version 4.3.0. Audit the Consul catalog for service registrations containing non-standard secure metadata values. Restrict write access to the Consul service registration API to trusted services.

Exploit

Fix

DoS

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81516
GHSA-67C9-F6V2-QV86

Affected Products

Hashicorp Consul
Steeltoe