{"id":"src_tvZpH9DDErf_GhX3yYM5M","slug":"consul-releases","name":"Consul","type":"github","url":"https://github.com/hashicorp/consul","orgId":"org_Yj55_xJFX2PSbzXjXof_V","productId":"prod_rDBF75fbHjtSYXB38dEpp","productSlug":"consul","org":{"id":"org_Yj55_xJFX2PSbzXjXof_V","slug":"hashicorp","name":"HashiCorp"},"isPrimary":false,"isHidden":false,"discovery":"curated","metadata":"{\"evaluatedMethod\":\"github\",\"evaluatedAt\":\"2026-04-07T23:43:09.586Z\",\"changelogUrl\":\"https://github.com/hashicorp/consul/blob/HEAD/CHANGELOG.md\",\"changelogDetectedAt\":\"2026-04-08T00:16:48.489Z\",\"wellKnownSweptAt\":\"2026-10-01T06:01:26.362Z\",\"sourceActor\":{\"nextAlarmAt\":\"2026-10-09T06:41:08.532Z\",\"lastAlarmAt\":\"2026-10-08T06:41:09.465Z\",\"managed\":true}}","notice":null,"kind":"platform","stars":30094,"starsFetchedAt":"2026-10-08T06:42:47.128Z","releaseCount":100,"releasesLast30Days":1,"avgReleasesPerWeek":0.2,"latestVersion":"v2.0.4","latestDate":"2026-09-10T06:12:16.000Z","changelogUrl":"https://github.com/hashicorp/consul/blob/HEAD/CHANGELOG.md","hasChangelogFile":true,"lastFetchedAt":"2026-10-08T06:42:47.128Z","lastPolledAt":"2026-10-08T06:42:43.312Z","changeDetectedAt":null,"trackingSince":"2024-01-23T20:20:24.000Z","releases":[{"id":"rel_RE3vtSmHDuOdcLVqnbzJa","version":"v2.0.4","type":"feature","title":"v2.0.4","summary":"Fixes a pre-authorization memory exhaustion vulnerability where an mTLS-authenticated RPC client with no ACL token could OOM-kill a Consul server with an oversized MessagePack header, plus an incorrect authorization vulnerability letting local tokens delete peer-imported catalog objects. Also requires mesh:write in addition to service:write for attaching code-executing EnvoyExtensions and proxy escape-hatch keys, and upgrades Go, golang.org/x/mod, x/crypto, and x/net to address security vulnerabilities.","titleGenerated":"Consul 2.0.4 patches memory-exhaustion and catalog authorization vulnerabilities","titleShort":"Consul 2.0.4 closes RPC memory-exhaustion and catalog authz holes","breaking":"major","importance":4,"content":"## 2.0.4 (September 10, 2026)\r\nBREAKING CHANGES:\r\n\r\n* acl: Tokens that hold service:write but not mesh:write will now receive a permission-denied error when attempting to attach builtin/lua or builtin/wasm EnvoyExtensions (or upstream envoy_listener_json/envoy_cluster_json escape-hatch overrides) to a service-defaults config entry, or when registering a connect-proxy sidecar with bootstrap or xDS escape-hatch keys set in the top-level Proxy.Config map or per-upstream in Proxy.Upstreams[*].Config. Operators must grant mesh:write to any token that legitimately needs these capabilities. [[GH-23864](https://github.com/hashicorp/consul/issues/23864)]\r\n* fips: **(Enterprise only)** FIPS release artifacts are renamed. Version metadata changes from `+ent.fips1402` to `+ent.fips1403`, and package and container artifacts change from the `F2` suffix to `F3` (for example, `consul-F2_1.20.4-1_amd64.deb` becomes `consul-F3_1.20.4-1_amd64.deb`). Pipelines that pin FIPS artifact names or version strings must be updated.\r\n\r\nSECURITY:\r\n\r\n* Upgrade go version to 1.26.7 to address security vulnerabilities. [[GH-23869](https://github.com/hashicorp/consul/issues/23869)]\r\n* acl: Require mesh:write in addition to service:write when attaching code-executing EnvoyExtensions (builtin/lua, builtin/wasm) or upstream escape-hatch overrides (envoy_listener_json, envoy_cluster_json in UpstreamConfig defaults or overrides) to a service-defaults config entry. Previously a holder of service:write on a service could attach a Lua script or Wasm module, or an upstream escape-hatch override, that Envoy compiled and executed on every proxied request as the sidecar process user, with access to mTLS private keys, request bodies, and the host filesystem. [[GH-23864](https://github.com/hashicorp/consul/issues/23864)]\r\n* acl: Require mesh:write in addition to service:write when registering a connect-proxy sidecar with bootstrap or xDS escape-hatch keys, whether set in the top-level Proxy.Config map or per-upstream in Proxy.Upstreams[*].Config (envoy_bootstrap_json_tpl, envoy_extra_static_listeners_json, envoy_public_listener_json, envoy_listener_json, envoy_cluster_json, envoy_local_cluster_json, envoy_extra_static_clusters_json, envoy_extra_stats_sinks_json, envoy_tracing_json, envoy_stats_config_json, envoy_listener_tracing_json). Key matching is case-insensitive to match the mapstructure decoding used downstream. Previously a holder of service:write on the proxy and its destination could inject arbitrary Envoy filter chain configuration into the sidecar bootstrap or xDS resources, including via a per-upstream override or a mixed-case key. [[GH-23864](https://github.com/hashicorp/consul/issues/23864)]\r\n* agent: Fixed a pre-authorization memory exhaustion vulnerability where\r\nan mTLS-authenticated RPC client with no ACL token could terminate a Consul server by\r\nsending a MessagePack request header with a large declared length. The MessagePack\r\ndecoder allocated a byte slice of the declared size before method lookup, ACL token\r\nvalidation, or the rate-limiting interceptor could run, allowing a single oversized\r\nheader to OOM-kill the server process.\r\n\r\nTwo mitigations are applied:\r\n\r\n1. Each RPC request header is now validated against RPCMaxHeaderBytes (default 512\r\n   bytes) before it is decoded. Every length prefix in the header is checked against\r\n   the limit, so an oversized value is rejected before the decoder allocates memory\r\n   for it, and the connection is closed before any ACL evaluation. Request bodies\r\n   remain unbounded by this limit.\r\n\r\n2. A per-request read deadline (reusing RPCHandshakeTimeout) is applied inside\r\n   handleConsulConn and handleInsecureConn so that a slow attacker trickling an\r\n   oversized header cannot retain a goroutine and logical heap indefinitely.\r\n* catalog: Fixed an incorrect authorization vulnerability where a local\r\nACL token with `service:write` or `node:write` could delete peer-imported catalog\r\nobjects by supplying a non-default `PeerName` in a `Catalog.Deregister` request.\r\nAuthorization was checked only against the local service or node name, not the peer\r\norigin, allowing deletion of objects in a peer-scoped catalog namespace the caller\r\ndoes not control. `Catalog.Deregister` now rejects any request whose `PeerName` is\r\nnot the default, mirroring the existing guard on `Catalog.Register` and\r\n`Catalog.ListServices`. Legitimate peer-state deletion continues through the internal\r\n`PeeringBackend.CatalogDeregister` path.\r\n* security: Upgrade golang.org/x/mod to v0.41.0, golang.org/x/crypto to v0.57.0, and golang.org/x/net to v0.59.0 to address security vulnerabilities. [[GH-23913](https://github.com/hashicorp/consul/issues/23913)]\r\n* xds: escape regex metacharacters in service name, namespace, partition, and trust domain values when building Envoy RBAC SPIFFE match patterns, preventing an intention/authorization bypass via regex injection.\r\n\r\nIMPROVEMENTS:\r\n\r\n* fips: **(Enterprise only)** Migrate FIPS builds from FIPS 140-2 (BoringCrypto/CNG cgo toolchain) to FIPS 140-3 using the Go Cryptographic Module (`GOFIPS140=v1.0.0`, CMVP Certificate #5247). The runtime FIPS line now reports `FIPS 140-3 Enabled, crypto module v1.0.0`. FIPS builds no longer require cgo or a vendored Go toolchain. FIPS 140-2 and FIPS 140-3 agents are permitted to join the same cluster; rolling upgrades from `+ent.fips1402` to `+ent.fips1403` are supported.\r\n\r\nBUG FIXES:\r\n\r\n* api-gateway: Fix a cold-start crash where an api-gateway's Envoy proxy could\r\nsegfault during worker startup when a route's failover upstream was rendered as\r\nan aggregate cluster before its endpoints were assembled. Consul now holds each\r\nxDS stream's first push until the gateway's discovery-chain endpoints are ready\r\n(per-stream, first-push only, skipped for streams Envoy resumes, and bounded by\r\na 30s deadline), and renders a failover upstream as a plain EDS cluster instead\r\nof an aggregate whenever its member endpoints are not yet available -- restoring\r\nfull failover automatically once they arrive. Steady-state updates are never\r\nwithheld. [[GH-23892](https://github.com/hashicorp/consul/issues/23892)]\r\n* mesh: **(Enterprise only)** Fix named-port upstreams to a multiport service that has a configured service-router, service-splitter, or service-resolver. The service's declared default port continues to follow the configured discovery chain, while other named ports connect directly to that port on the root service instead of failing. Upstreams that do not name a port resolve through the default port.\r\n\r\n","publishedAt":"2026-09-10T06:12:16.000Z","fetchedAt":"2026-09-11T05:59:43.171Z","url":"https://github.com/hashicorp/consul/releases/tag/v2.0.4","media":[],"coverageCount":0},{"id":"rel_0iBvm5OfeqEHu9UKhWoe0","version":"v2.0.3","type":"feature","title":"v2.0.3","summary":"v2.0.3 addresses six security issues, including a cache-based DoS on connect endpoints, an unauthenticated heap-exhaustion via unbounded JSON bodies (now capped at 512 KiB), and an unbounded-connection DoS on gRPC listeners (new per-client-IP limiter, default 100). Also fixed a nil-pointer panic, a Gateway 503 regression, and a token-leak logging issue.","titleGenerated":"Consul v2.0.3 patches six security vulnerabilities and DoS risks","titleShort":"Six security fixes including cache DoS and request body bombs","breaking":"none","importance":4,"content":"## 2.0.3 (August 7, 2026)\nSECURITY:\n\n* Update `brace-expansion` to address [GHSA-rgw5-rvv9-x895](https://github.com/advisories/GHSA-rgw5-rvv9-x895) (DoS via unbounded intermediate arrays). [[GH-23786](https://github.com/hashicorp/consul/issues/23786)]\n* Update `fast-uri` to address [GHSA-7p8r-x3mc-p8w7](https://github.com/advisories/GHSA-7p8r-x3mc-p8w7) (Host Confusion via backslash authority introducer). [[GH-23786](https://github.com/hashicorp/consul/issues/23786)]\n* Update `golang.org/x/text` to v0.39.0 to address [GO-2026-5970](https://pkg.go.dev/vuln/GO-2026-5970). [[GH-23761](https://github.com/hashicorp/consul/issues/23761)]\n* Update `google.golang.org/grpc` to v1.82.1 to address [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf). [[GH-23761](https://github.com/hashicorp/consul/issues/23761)]\n* Update `socket.io-parser` to address [CVE-2026-69185](https://github.com/advisories/GHSA-2m8v-j782-fhvr) (Zero-attachment Memory Exhaustion). [[GH-23786](https://github.com/hashicorp/consul/issues/23786)]\n* Upgrade to use Go `1.26.5`. This resolves vulnerabilities\n[GO-2026-4970](https://pkg.go.dev/vuln/GO-2026-4970) (`os`).\n[GO-2026-5856](https://pkg.go.dev/vuln/GO-2026-5856) (`crypto/tls`). [[GH-23761](https://github.com/hashicorp/consul/issues/23761)]\n* agent: Fixed a denial-of-service vulnerability where `GET /v1/agent/connect/ca/roots`\nand `POST /v1/agent/connect/authorize` used the agent-side cache unconditionally, even\nwhen `http_config { use_cache = false }` was configured by the operator. A remote caller\ncould bypass this setting and grow the agent cache without bound by varying the request\nACL token. Both endpoints now skip the cache and issue a direct RPC when `use_cache` is\ndisabled. (SECVULN-50292, SECVULN-50293) [[GH-23797](https://github.com/hashicorp/consul/issues/23797)]\n* agent: Fixed a nil-pointer dereference panic in `ShadowServiceRouterConfigEntry.CheckEnt`\nwhen a service-router config entry contained a route with a nil `Destination`. A crafted\nsnapshot restore or replication message containing such an entry could crash the FSM\ndecode path. The nil guard now treats a missing destination as non-enterprise data and\ncontinues decoding safely. (SECVULN-50291) [[GH-23797](https://github.com/hashicorp/consul/issues/23797)]\n* agent: Fixed a security bypass where a user-supplied public listener\n(`envoy_public_listener_json`) with an HTTP Connection Manager filter would skip Consul's\ninbound request-normalization defaults. An attacker could exploit the un-normalized path\nto bypass L7 intention `deny` rules using percent-encoded path equivalents. Consul now\ninjects path normalization (enabled by default, unless the mesh config option\n`InsecureDisablePathNormalization` is set) on every HCM filter chain in user-provided\npublic listeners before L7 intention enforcement is applied. (SECVULN-50295) [[GH-23797](https://github.com/hashicorp/consul/issues/23797)]\n* agent: Fixed an unauthenticated denial-of-service vulnerability where\n`PUT /v1/agent/check/update/:id`, `PUT /v1/agent/check/register`,\n`PUT /v1/agent/service/register`, and `POST /v1/agent/connect/authorize`\ndecoded unbounded JSON request bodies before resolving the caller's ACL\ntoken. An unauthenticated caller could retain multiple large JSON decoder\nbuffers concurrently inside the Consul process before each request was\nrejected with HTTP 403, causing attacker-controlled heap growth. All four\nendpoints now cap the request body at 512 KiB before any decoding occurs,\nreturning HTTP 413 for oversized bodies. This limit applies to chunked\ntransfer encoding as well as declared `Content-Length`.\n(SECVULN-50418) [[GH-23796](https://github.com/hashicorp/consul/issues/23796)]\n* agent: Fixed an unauthenticated denial-of-service vulnerability where the external gRPC\nand gRPC-TLS listeners accepted an unlimited number of TCP connections per source IP\nbefore any request processing, ACL check, or rate limiting could occur. A remote attacker\ncould exhaust agent file descriptors, goroutines, and memory by opening many connections\nand withholding the gRPC or TLS handshake. A new per-client-IP connection limiter is now\napplied before the gRPC server observes the connection, controlled by the new\n`limits.grpc_max_conns_per_client` configuration option (default 100). The gRPC handshake\ntimeout has also been reduced from the library default of 120 seconds to 20 seconds.\n(SECVULN-50294) [[GH-23797](https://github.com/hashicorp/consul/issues/23797)]\n\nIMPROVEMENTS:\n\n* ui: migrate yadda/Gherkin acceptance tests to native QUnit (harness, intentions/create, components, settings) [[GH-23741](https://github.com/hashicorp/consul/issues/23741)]\n* xds: Add two new opt-in `ProxyDefaults.spec.config` keys for controlling the `server` response header on API Gateway HTTP listeners: `envoy_suppress_envoy_headers` (removes the header entirely) and `envoy_server_header_name` (renames it to a custom value). If both are set, suppress takes precedence. [[GH-13027](https://github.com/hashicorp/consul/issues/13027)]\n\nBUG FIXES:\n\n* agent: Stop logging the raw ACL token in debug-level content-type logs. [[GH-23731](https://github.com/hashicorp/consul/issues/23731)]\n* api-gateway: Fixed a regression that caused an HTTP API gateway to reject its configuration with an \"inconsistent protocols\" error (resulting in intermittent 503s) when a backend service's `service-router` composed a route to a destination in a different service, namespace, or partition during discovery-chain synthesis. [[GH-23793](https://github.com/hashicorp/consul/issues/23793)]\n* serf: Fix WAN flood-join to ignore non-alive destination members (leaving/left/failed), allowing rejoined servers to heal back to alive in WAN membership. [[GH-23709](https://github.com/hashicorp/consul/issues/23709)]\n* xds: Addition of XFCC headers to GPRC request similar to HTTP request for connect-proxy inbound listener [[GH-23744](https://github.com/hashicorp/consul/issues/23744)]\n\n\n","publishedAt":"2026-08-07T17:25:55.000Z","fetchedAt":"2026-08-08T05:05:25.973Z","url":"https://github.com/hashicorp/consul/releases/tag/v2.0.3","media":[],"coverageCount":0},{"id":"rel_dl_ogVCcSHjQLGzMnkhXd","version":"v2.0.2","type":"feature","title":"v2.0.2","summary":"Upgraded Alpine base image to 3.24 to address CVE-2026-41989 and ALPINE-CVE-2026-2100, and upgraded Serf and Memberlist to their latest versions. XDS now returns errors when injecting L4 intention (RBAC) filter or mTLS transport socket onto inbound public listeners without enforcement, preventing listeners from being served without intention enforcement or mTLS. Also added ExtAuthzFilter support to HTTPRoute Filters and gateway-wide ExtAuthz toggle for api-gateway (Enterprise only), and External Processor (ext_proc) Envoy Extension support for api-gateway and connect-proxy (Enterprise only).","titleGenerated":"Consul v2.0.2 addresses CVE-2026-41989 and hardens intention enforcement","titleShort":"Alpine base image updated; intention enforcement hardened","breaking":"none","importance":4,"content":"## 2.0.2 (July 8, 2026)\nSECURITY:\n\n* Upgrade alpine base image version to 3.24 to address [CVE-2026-41989], [ALPINE-CVE-2026-2100]. [[GH-23711](https://github.com/hashicorp/consul/issues/23711)]\n* dependency: Upgrade Serf and Memberlist to use the latest versions. [[GH-23704](https://github.com/hashicorp/consul/issues/23704)]\n* xds: Return errors when injecting the L4 intention (RBAC) filter or the mTLS transport socket onto an inbound public listener, so the listener is not served without intention enforcement or mTLS. [[GH-23686](https://github.com/hashicorp/consul/issues/23686)]\n\nFEATURES:\n\n* config-entry(api-gateway): (Enterprise only) Add ExtAuthzFilter to HTTPRoute Filters and gateway-wide ExtAuthz toggle to the api-gateway config entry [[GH-23703](https://github.com/hashicorp/consul/issues/23703)]\n* config-entry: (Enterprise only) Addition of External Processor (ext_proc) Envoy Extension support to api-gateway and connect-proxy [[GH-23705](https://github.com/hashicorp/consul/issues/23705)]\n\nIMPROVEMENTS:\n\n* ci: upgrade GitHub Actions that used the deprecated Node 20 runtime to Node 24, and restore GOTOOLCHAIN=auto after setup-go so backward-compatibility and integration test lanes resolve the correct Go toolchain. [[GH-23687](https://github.com/hashicorp/consul/issues/23687)]\n* connect: update support for nomad and vault version to v2.0.3 [[GH-23624](https://github.com/hashicorp/consul/issues/23624)]\n* deps: Migrate `armon/go-metrics` to `hashicorp/go-metrics` and update Go dependencies across all modules [[GH-23635](https://github.com/hashicorp/consul/issues/23635)]\n\nBUG FIXES:\n\n* xds: only emit the client cert SDS block when both CertFile and KeyFile are set. [[GH-23679](https://github.com/hashicorp/consul/issues/23679)]\n\n\n","publishedAt":"2026-07-08T10:39:04.000Z","fetchedAt":"2026-07-09T04:17:56.316Z","url":"https://github.com/hashicorp/consul/releases/tag/v2.0.2","media":[],"coverageCount":0},{"id":"rel_8pLk-oNkmldLsMeqoQNxQ","version":"v2.0.1","type":"feature","title":"v2.0.1","summary":"Fixed a bug where renaming or rejoining a server could evict the live leader from the internal server lookup, causing Raft leader errors on follower RPCs. Inbound HTTP requests now have the x-forwarded-client-cert header stripped before forwarding to local services. Also includes Go and Envoy security upgrades, OIDC/JWT claim mapping support for auth method token names, and product telemetry export cadence preservation across restarts.","titleGenerated":"Consul v2.0.1 fixes leader eviction bug and strips x-forwarded-client-cert header","titleShort":"Leader eviction on server rename fixed; x-forwarded-client-cert stripped","breaking":"unknown","importance":null,"content":"## 2.0.1 (June 18, 2026)\n\nSECURITY:\n\n* Upgrade go version to 1.26.4 to address [GO-2026-5039](https://pkg.go.dev/vuln/GO-2026-5039), [GO-2026-5038](https://pkg.go.dev/vuln/GO-2026-5038),[GO-2026-5037](https://pkg.go.dev/vuln/GO-2026-5037) [[GH-23637](https://github.com/hashicorp/consul/issues/23637)]\n* connect: Upgrade envoy version to 1.37.4, 1.36.8, 1.35.12; Add new version of Envoy 1.38.2 and remove 1.34.14 [[GH-23664](https://github.com/hashicorp/consul/issues/23664)]\n\nIMPROVEMENTS:\n\n* dockerfile: layer reduction by merging RUN commands and minor changes following best practices. [[GH-23650](https://github.com/hashicorp/consul/issues/23650)]\n* product-telemetry: product usage reporting now preserves export cadence across restarts and leader re-elections by resuming from the last successful export time, preventing delays\n* server: Auth method TokenNameFormat field accepts OIDC and JWT claim mapping values [[GH-23616](https://github.com/hashicorp/consul/issues/23616)]\n* ui: Removed block-slot addon dependency [[GH-23481](https://github.com/hashicorp/consul/issues/23481)]\n\nBUG FIXES:\n\n* connect: Strip the `x-forwarded-client-cert` header from inbound HTTP requests before forwarding them to local service instances. [[GH-23544](https://github.com/hashicorp/consul/issues/23544)]\n* server: Fixed a bug where renaming a server (or wiping and rejoining it with the same IP and Raft node ID) could cause an out-of-order serf event to evict the live leader from the internal server lookup, resulting in `Raft leader not found in server lookup mapping` (HTTP 500) errors on follower RPCs until the next member event resynced the mapping. [[GH-23533](https://github.com/hashicorp/consul/issues/23533)]\n\n# 2.0.0 (May 22, 2026)\n\nSECURITY:\n\n* connect: Upgrade envoy version to 1.37.2 and newer versions [[GH-23469](https://github.com/hashicorp/consul/pull/23469)]\n* go: Upgrade go version to 1.26 [[GH-23493](https://github.com/hashicorp/consul/pull/23493)]\n* agent: Increased default HTTP server timeouts to prevent breaking long-polling blocking queries. `read_timeout` and `write_timeout` are now set to 15 minutes (up from 30 seconds), while `read_header_timeout` (10s) and `idle_timeout` (120s) still provide protection against Slowloris attacks. All timeouts remain configurable via the `http_config` block. [[GH-23267](https://github.com/hashicorp/consul/issues/23267)]\n* api-gateway, terminating-gateway: Apply HTTP request path normalization on api-gateway and terminating-gateway HTTP listeners to prevent L7 intention RBAC bypass via non-normalized paths (CVE-2024-10005). [[GH-23534](https://github.com/hashicorp/consul/issues/23534)]\n* docker: update ubi base image to `ubi9-minimal:9.7`. [[GH-23553](https://github.com/hashicorp/consul/issues/23553)]\n* docker: Upgrade `curl` to >= 8.20.0 from Alpine edge in the container image to address\n[CVE-2026-6429](https://www.cve.org/CVERecord?id=CVE-2026-6429),\n[CVE-2026-4873](https://www.cve.org/CVERecord?id=CVE-2026-4873),\n[CVE-2026-5773](https://www.cve.org/CVERecord?id=CVE-2026-5773),\n[CVE-2026-6253](https://www.cve.org/CVERecord?id=CVE-2026-6253),\n[CVE-2026-6276](https://www.cve.org/CVERecord?id=CVE-2026-6276),\n[CVE-2026-7168](https://www.cve.org/CVERecord?id=CVE-2026-7168),\n[CVE-2026-5545](https://www.cve.org/CVERecord?id=CVE-2026-5545).\nAlpine 3.23 stable does not yet carry the patched version. [[GH-23750](https://github.com/hashicorp/consul/issues/23750)]\n* docker: Update to UBI base image to 9.8 for fixing [[CVE_2026-2100](https://access.redhat.com/security/cve/cve-2026-2100)] [[GH-23588](https://github.com/hashicorp/consul/issues/23588)]\n\nFEATURES:\n\n* **(Enterprise Only)** update to go-licensing/v4 and go-census/v3 inorder to adapt to new licenses of PAO.\n* Global Rate Limiter: **(Enterprise Only)** a new \"rate-limit\" config entry kind that enables dynamic, cluster-wide RPC rate limiting stored in Raft and automatically replicated to all servers. This allows operators to apply or adjust global rate limits at runtime without restarting Consul servers — a critical capability for emergency scenarios where the cluster is under excessive load.\n* api-gateway: Added SDS certificate support for API Gateway listeners, including listener-level default TLS certificates and HTTP/TCP route service TLS SDS overrides. Service overrides inherit the listener SDS cluster when omitted, and gateway validation/xDS generation now rejects conflicting override mappings to keep certificate selection deterministic. [[GH-23354](https://github.com/hashicorp/consul/pull/23354)]\n* api-gateway: add support for gateway-level default upstream limits and route service-level limit overrides for MaxConnections, MaxPendingRequests, and MaxConcurrentRequests. [[GH-23396](https://github.com/hashicorp/consul/pull/23396)]\n* api: Added new API \"/v1/internal/rpc/methods\" that lists all RPC method names. Requires an operator:read ACL token. This is useful when users want to configure rate limits that exclude specific RPC endpoints. [[GH-23329](https://github.com/hashicorp/consul/pull/23329)]\n* ca: **(Enterprise Only)** Added new Connect CA provider for Cyberark WIM (connect.ca_provider = \"pan-distributed-issuer\"), enabling Consul to issue certificates through Cyberark WIM.\n* server: **(Enterprise Only)** add stable cluster identity and leader-gated global registry sync for service summary publishing.\n* telemetry: **(Enterprise Only)** Product telemetry for self-managed Consul with anonymous, opt-in usage reporting.\n* mesh: **(Enterprise Only)** Introduce support for multi-port (named port) services in Consul, including the ability to specify and route traffic using port names, as well as to retrieve virtual IPs for specific service ports. It also enforces that certain advanced multi-port features are only available in Consul Enterprise, and includes new utility functions for cluster naming and ALPN protocol generation.\n\nIMPROVEMENTS:\n\n* agent: **(Enterprise Only)** Add eventually-consistent background cache for Enterprise usage metrics, reducing GET /v1/operator/usage latency from O(P*N*K) to O(1) and lowering CPU/memory pressure during high-frequency scraping via a watch-driven maintainer goroutine.\n* mesh: **(Enterprise Only)** Introduce support for multi-port (named port) services in Consul, including the ability to specify and route traffic using port names, as well as to retrieve virtual IPs for specific service ports. It also enforces that certain advanced multi-port features are only available in Consul Enterprise, and includes new utility functions for cluster naming and ALPN protocol generation.\n* terminating-gateway: Updated the cluster upstream tls to use sds instead of static certs, allowing for dynamic certificate updates without needing to restart the terminating gateway. [[GH-23288](https://github.com/hashicorp/consul/pull/23288)]\n* telemetry: Add certificate expiry monitoring with Prometheus metrics (labeled with datacenter/partition/namespace), structured logging with configurable severity thresholds, and enhanced Connect CA API to include NotAfter field for root and intermediate certificates. [[GH-23147](https://github.com/hashicorp/consul/pull/23147)]\n* deps: Upgrade `github.com/hashicorp/vault/sdk` from v0.7.0 to v0.25.1 and `github.com/hashicorp/vault/api` from v1.12.2 to v1.16.0. [[GH-23574](https://github.com/hashicorp/consul/issues/23574)]\n* test-integ: upgrade testcontainers-go (v0.22.0->v0.40.0) and docker/docker (v24.0.5->v28.5.1) in the integration test module. This removes opencontainers/runc as a Go dependency of the test framework. These are test infrastructure dependencies only and have no impact on the consul binary or any consul deployment. [[GH-23573](https://github.com/hashicorp/consul/issues/23573)]\n* xds: **(Enterprise Only)** add `Consecutive5xx`, `ConsecutiveGatewayFailure`, and `EnforcingConsecutiveGatewayFailure` fields to `PassiveHealthCheck`, allowing operators to configure Envoy outlier detection thresholds for 5xx responses and gateway failures (502/503/504) on upstreams defaults.\n\nBUG FIXES:\n\n* audit-logging: **(Enterprise Only)** Fixed JSON unmarshall error when array of obj is passed for auditReq body.\n* cli: Enhanced error messages in `consul config write` command to provide actionable guidance when config entries cannot be modified due to references by gateways or routers. [[GH-22921](https://github.com/hashicorp/consul/pull/22921)]\n* xds: Fixed XDS package to generate correct endpoints and cluster configurations for API Gateways when peered, and updated the API Gateway update handler to propogate mesh gateway config to its upstreams. [[GH-23454](https://github.com/hashicorp/consul/pull/23454)]\n* XDS: Fixes issue with mesh-gateway in remote mode on AWS EKS, as DNS hostnames are assigned to AWS NLBs instead of IPs and envoy's EDS endpoint validation expects address to be an IP. Now EDS load assignment is skipped for non-peer remote mesh gateway targets with hostname based gateways keeping CDS/EDS in sync. [[GH-23543](https://github.com/hashicorp/consul/issues/23543)]\n* api-gateway: resolve service subsets for routes during API gateway discovery chain synthesis. [[GH-23294](https://github.com/hashicorp/consul/issues/23294)]\n* ui: Fix broken documentation links [[GH-23578](https://github.com/hashicorp/consul/issues/23578)]\n\n","publishedAt":"2026-06-19T07:23:26.000Z","fetchedAt":"2026-06-19T18:01:53.628Z","url":"https://github.com/hashicorp/consul/releases/tag/v2.0.1","media":[],"coverageCount":0},{"id":"rel_oQfT3I6rHLXM0wm2AD53-","version":"v2.0.0","type":"feature","title":"v2.0.0","summary":"Applied HTTP request path normalization on API Gateway and Terminating Gateway listeners to prevent L7 intention RBAC bypass via non-normalized paths (CVE-2024-10005). Enterprise deployments gain a new \"rate-limit\" config entry that enables dynamic, cluster-wide RPC rate limiting stored in Raft and automatically replicated to all servers. Also upgraded Envoy to 1.37.2, Go to 1.26, and patched multiple curl CVEs in the Docker container image.","titleGenerated":"Consul v2.0.0 patches CVE-2024-10005 gateway RBAC bypass and adds rate limiting","titleShort":"Gateway RBAC bypass fixed; global rate limiter added (Enterprise)","breaking":"unknown","importance":null,"content":"## 2.0.0 (May 22, 2026)\n\nSECURITY:\n\n* connect: Upgrade envoy version to 1.37.2 and newer versions [[GH-23469](https://github.com/hashicorp/consul/pull/23469)]\n* go: Upgrade go version to 1.26 [[GH-23493](https://github.com/hashicorp/consul/pull/23493)]\n* agent: Increased default HTTP server timeouts to prevent breaking long-polling blocking queries. `read_timeout` and `write_timeout` are now set to 15 minutes (up from 30 seconds), while `read_header_timeout` (10s) and `idle_timeout` (120s) still provide protection against Slowloris attacks. All timeouts remain configurable via the `http_config` block. [[GH-23267](https://github.com/hashicorp/consul/issues/23267)]\n* api-gateway, terminating-gateway: Apply HTTP request path normalization on api-gateway and terminating-gateway HTTP listeners to prevent L7 intention RBAC bypass via non-normalized paths (CVE-2024-10005). [[GH-23534](https://github.com/hashicorp/consul/issues/23534)]\n* docker: update ubi base image to `ubi9-minimal:9.7`. [[GH-23553](https://github.com/hashicorp/consul/issues/23553)]\n* docker: Upgrade `curl` to >= 8.20.0 from Alpine edge in the container image to address\n[CVE-2026-6429](https://www.cve.org/CVERecord?id=CVE-2026-6429),\n[CVE-2026-4873](https://www.cve.org/CVERecord?id=CVE-2026-4873),\n[CVE-2026-5773](https://www.cve.org/CVERecord?id=CVE-2026-5773),\n[CVE-2026-6253](https://www.cve.org/CVERecord?id=CVE-2026-6253),\n[CVE-2026-6276](https://www.cve.org/CVERecord?id=CVE-2026-6276),\n[CVE-2026-7168](https://www.cve.org/CVERecord?id=CVE-2026-7168),\n[CVE-2026-5545](https://www.cve.org/CVERecord?id=CVE-2026-5545).\nAlpine 3.23 stable does not yet carry the patched version. [[GH-23750](https://github.com/hashicorp/consul/issues/23750)]\n* docker: Update to UBI base image to 9.8 for fixing [[CVE_2026-2100](https://access.redhat.com/security/cve/cve-2026-2100)] [[GH-23588](https://github.com/hashicorp/consul/issues/23588)]\n\nFEATURES:\n\n* **(Enterprise Only)** update to go-licensing/v4 and go-census/v3 inorder to adapt to new licenses of PAO.\n* Global Rate Limiter: **(Enterprise Only)** a new \"rate-limit\" config entry kind that enables dynamic, cluster-wide RPC rate limiting stored in Raft and automatically replicated to all servers. This allows operators to apply or adjust global rate limits at runtime without restarting Consul servers — a critical capability for emergency scenarios where the cluster is under excessive load.\n* api-gateway: Added SDS certificate support for API Gateway listeners, including listener-level default TLS certificates and HTTP/TCP route service TLS SDS overrides. Service overrides inherit the listener SDS cluster when omitted, and gateway validation/xDS generation now rejects conflicting override mappings to keep certificate selection deterministic. [[GH-23354](https://github.com/hashicorp/consul/pull/23354)]\n* api-gateway: add support for gateway-level default upstream limits and route service-level limit overrides for MaxConnections, MaxPendingRequests, and MaxConcurrentRequests. [[GH-23396](https://github.com/hashicorp/consul/pull/23396)]\n* api: Added new API \"/v1/internal/rpc/methods\" that lists all RPC method names. Requires an operator:read ACL token. This is useful when users want to configure rate limits that exclude specific RPC endpoints. [[GH-23329](https://github.com/hashicorp/consul/pull/23329)]\n* ca: **(Enterprise Only)** Added new Connect CA provider for Cyberark WIM (connect.ca_provider = \"pan-distributed-issuer\"), enabling Consul to issue certificates through Cyberark WIM.\n* server: **(Enterprise Only)** add stable cluster identity and leader-gated global registry sync for service summary publishing.\n* telemetry: **(Enterprise Only)** Product telemetry for self-managed Consul with anonymous, opt-in usage reporting.\n* mesh: **(Enterprise Only)** Introduce support for multi-port (named port) services in Consul, including the ability to specify and route traffic using port names, as well as to retrieve virtual IPs for specific service ports. It also enforces that certain advanced multi-port features are only available in Consul Enterprise, and includes new utility functions for cluster naming and ALPN protocol generation.\n\nIMPROVEMENTS:\n\n* agent: **(Enterprise Only)** Add eventually-consistent background cache for Enterprise usage metrics, reducing GET /v1/operator/usage latency from O(P*N*K) to O(1) and lowering CPU/memory pressure during high-frequency scraping via a watch-driven maintainer goroutine.\n* mesh: **(Enterprise Only)** Introduce support for multi-port (named port) services in Consul, including the ability to specify and route traffic using port names, as well as to retrieve virtual IPs for specific service ports. It also enforces that certain advanced multi-port features are only available in Consul Enterprise, and includes new utility functions for cluster naming and ALPN protocol generation.\n* terminating-gateway: Updated the cluster upstream tls to use sds instead of static certs, allowing for dynamic certificate updates without needing to restart the terminating gateway. [[GH-23288](https://github.com/hashicorp/consul/pull/23288)]\n* telemetry: Add certificate expiry monitoring with Prometheus metrics (labeled with datacenter/partition/namespace), structured logging with configurable severity thresholds, and enhanced Connect CA API to include NotAfter field for root and intermediate certificates. [[GH-23147](https://github.com/hashicorp/consul/pull/23147)]\n* deps: Upgrade `github.com/hashicorp/vault/sdk` from v0.7.0 to v0.25.1 and `github.com/hashicorp/vault/api` from v1.12.2 to v1.16.0. [[GH-23574](https://github.com/hashicorp/consul/issues/23574)]\n* test-integ: upgrade testcontainers-go (v0.22.0->v0.40.0) and docker/docker (v24.0.5->v28.5.1) in the integration test module. This removes opencontainers/runc as a Go dependency of the test framework. These are test infrastructure dependencies only and have no impact on the consul binary or any consul deployment. [[GH-23573](https://github.com/hashicorp/consul/issues/23573)]\n* xds: **(Enterprise Only)** add `Consecutive5xx`, `ConsecutiveGatewayFailure`, and `EnforcingConsecutiveGatewayFailure` fields to `PassiveHealthCheck`, allowing operators to configure Envoy outlier detection thresholds for 5xx responses and gateway failures (502/503/504) on upstreams defaults.\n\nBUG FIXES:\n\n* audit-logging: **(Enterprise Only)** Fixed JSON unmarshall error when array of obj is passed for auditReq body.\n* cli: Enhanced error messages in `consul config write` command to provide actionable guidance when config entries cannot be modified due to references by gateways or routers. [[GH-22921](https://github.com/hashicorp/consul/pull/22921)]\n* xds: Fixed XDS package to generate correct endpoints and cluster configurations for API Gateways when peered, and updated the API Gateway update handler to propogate mesh gateway config to its upstreams. [[GH-23454](https://github.com/hashicorp/consul/pull/23454)]\n* XDS: Fixes issue with mesh-gateway in remote mode on AWS EKS, as DNS hostnames are assigned to AWS NLBs instead of IPs and envoy's EDS endpoint validation expects address to be an IP. Now EDS load assignment is skipped for non-peer remote mesh gateway targets with hostname based gateways keeping CDS/EDS in sync. [[GH-23543](https://github.com/hashicorp/consul/issues/23543)]\n* api-gateway: resolve service subsets for routes during API gateway discovery chain synthesis. [[GH-23294](https://github.com/hashicorp/consul/issues/23294)]\n* ui: Fix broken documentation links [[GH-23578](https://github.com/hashicorp/consul/issues/23578)]\n\n","publishedAt":"2026-05-24T05:55:03.000Z","fetchedAt":"2026-05-24T07:02:21.577Z","url":"https://github.com/hashicorp/consul/releases/tag/v2.0.0","media":[],"coverageCount":0},{"id":"rel_VuYYvprLPqdBCUdwVmhBS","version":"v1.22.7","type":"feature","title":"v1.22.7","summary":"## 1.22.7 (April 21, 2026)\n\nSECURITY:\n\n* security: update google.golang.org/grpc to fix CVE-2026-33186 [[GH-23379](https://github.com/hashicorp/consul...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.22.7 (April 21, 2026)\n\nSECURITY:\n\n* security: update google.golang.org/grpc to fix CVE-2026-33186 [[GH-23379](https://github.com/hashicorp/consul/issues/23379)]\n* security: upgrade go.opentelemetry.io/otel to 1.42.0 to remediate CVE-2026-24051 (Path Hijacking / Untrusted Search Paths on macOS). [[GH-23387](https://github.com/hashicorp/consul/issues/23387)]\n* test-sds-server: bump github.com/hashicorp/consul to v1.22.5 in integration test module to align with the CVE-2026-2808 fixed release line. [[GH-23437](https://github.com/hashicorp/consul/issues/23437)]\n* ui: **(Enterprise only)** Backport Rollup update to 2.80.0 for release/1.21.x to address CVE-2026-27606 (SECVULN-38912). [[GH-23359](https://github.com/hashicorp/consul/issues/23359)]\n\nIMPROVEMENTS:\n\n* acl: Addition of TokenNameFormat field to auth-method and parse the same for token name [[GH-23444](https://github.com/hashicorp/consul/issues/23444)]\n* discovery-chain: removes the use of hashstructure_v2 ([github.com/mitchellh/hashstructure/v2] from compiled discovery chain hashing and replaces it with explicit custom hash implementations. [[GH-23393](https://github.com/hashicorp/consul/issues/23393)]\n* ui: removed consul docs website related code as it is being maintained in a separate internal repository. [[GH-23398](https://github.com/hashicorp/consul/issues/23398)]\n\nBUG FIXES:\n\n* api-gateway: fix HTTPRoute PathPrefix routing to preserve the original request path when `replacePrefixMatch` is not configured [[GH-23390](https://github.com/hashicorp/consul/issues/23390)]\n\n","publishedAt":"2026-04-25T07:38:41.000Z","fetchedAt":"2026-04-25T12:00:56.641Z","url":"https://github.com/hashicorp/consul/releases/tag/v1.22.7","media":[],"coverageCount":0},{"id":"rel_djRbvM5JO0D046q3Blid-","version":"v1.22.6","type":"feature","title":"v1.22.6","summary":"## 1.22.6 (March 23, 2026)\n\nSECURITY:\n\n* security: upgrade envoy version to 1.35.9 and 1.34.13 [[GH-23372](https://github.com/hashicorp/consul/pull/23...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.22.6 (March 23, 2026)\n\nSECURITY:\n\n* security: upgrade envoy version to 1.35.9 and 1.34.13 [[GH-23372](https://github.com/hashicorp/consul/pull/23372)]\n* security: update google.golang.org/grpc to fix CVE-2026-33186 [[GH-23379](https://github.com/hashicorp/consul/pull/23379)]\n* security: upgrade go version to 1.25.8 [[GH-23322](https://github.com/hashicorp/consul/pull/23322)]\n* security: bump golang.org/x/* dependencies to align with consul-enterprise and address security vulnerabilities. [[GH-23322](https://github.com/hashicorp/consul/pull/23322)]\n\nIMPROVEMENTS:\n\n* api-gateway: Add support to disable traffic with weight 0 in services for HTTPRoute backends, allowing explicit zero-weight backends to be excluded from traffic. [[GH-23216](https://github.com/hashicorp/consul/pull/23216)]\n* ui: Fixed Consul UI to work in non-secure environments by enabling Ember Data's UUID polyfill for crypto.randomUUID. [[GH-23341](https://github.com/hashicorp/consul/pull/23341)]\n* ui: Fixed Consul UI services page navigation by ensuring route transitions trigger the expected model hook behavior after Ember upgrade. [[GH-23271](https://github.com/hashicorp/consul/pull/23271)]\n* ui: Replaced deprecated SideNav component with AppSideNav for improved navigation structure. [[GH-23289](https://github.com/hashicorp/consul/pull/23289)]\n\n","publishedAt":"2026-03-26T10:44:17.000Z","fetchedAt":"2026-04-08T00:01:05.496Z","url":"https://github.com/hashicorp/consul/releases/tag/v1.22.6","media":[],"coverageCount":0},{"id":"rel_pj1dpz4v-aziWaSNxvNzr","version":"v1.22.5","type":"feature","title":"v1.22.5","summary":"## 1.22.5 (February 26, 2026)\n\nSECURITY:\n* security: upgrade go version to 1.25.7 [[GH-23204](https://github.com/hashicorp/consul/issues/23204)]\n* doc...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.22.5 (February 26, 2026)\n\nSECURITY:\n* security: upgrade go version to 1.25.7 [[GH-23204](https://github.com/hashicorp/consul/issues/23204)]\n* dockerfile: the Consul build Go base image to `alpine3.23` [[GH-23194](https://github.com/hashicorp/consul/issues/23194)]\n* connect: Migrate to aws-sdk-go-v2 from aws-sdk-go (v1). Also updated consul-awsauth and go-secure-stdlib/awsutil dependencies to their v2 versions. [[GH-23109](https://github.com/hashicorp/consul/issues/23109)]\n* security: Configure HTTP server timeouts to prevent Slowloris denial-of-service attacks on agent HTTP endpoints and pprof endpoints. [[GH-22739](https://github.com/hashicorp/consul/issues/22739)]\n* security: Patched Vault CA provider to prevent arbitrary file reads via Kubernetes, JWT, and AppRole methods. [[GH-23249](https://github.com/hashicorp/consul/pull/23249)]\n* security: Introduced debounce timing for synchronization operations within federationStateAntiEntropySync. [[GH-23196](https://github.com/hashicorp/consul/pull/23196)]\n\nIMPROVEMENTS:\n* api-gateway: Fixed \"duplicate matcher\" errors in Envoy when using multiple file-system certificates on a single TLS listener. The certificates are now consolidated into a single filter chain, allowing Envoy to select the correct one. [[GH-23212](https://github.com/hashicorp/consul/issues/23212)]\n* agent: Fix vault provider failure when signing intermediate CA with isCA=true in CSR [[GH-23202](https://github.com/hashicorp/consul/issues/23202)]\n* cli: Added `--aws-iam-endpoint` flag to `consul login` command for AWS IAM auth method to support custom IAM endpoint configuration [[GH-23109](https://github.com/hashicorp/consul/issues/23109)]\n* docs: Refreshed the security documentation to include the new HTTP server timeout defaults and relevant configuration options. [[GH-23246](https://github.com/hashicorp/consul/pull/23246)]\n* api: Cancel context check for watches cache fetch to stop execution when manager deregisters the watch. [[GH-23157](https://github.com/hashicorp/consul/issues/23157)]\n\n","publishedAt":"2026-02-27T07:18:14.000Z","fetchedAt":"2026-04-08T00:01:05.496Z","url":"https://github.com/hashicorp/consul/releases/tag/v1.22.5","media":[],"coverageCount":0},{"id":"rel_r3Bp3onr8izoNLou7z5Bu","version":"v1.22.4","type":"feature","title":"v1.22.4","summary":"⚠️ Important Notice\r\n\r\n**We have identified an issue in Consul and Consul Enterprise Feb Patch Release (1.22.4, 1.22.4-ent, 1.21.10-ent, 1.18.20-ent) ...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"⚠️ Important Notice\r\n\r\n**We have identified an issue in Consul and Consul Enterprise Feb Patch Release (1.22.4, 1.22.4-ent, 1.21.10-ent, 1.18.20-ent) that requires a corrective patch release.**\r\n\r\n**We recommend that customers avoid using these versions in production environments and wait for the upcoming patch release.**\r\n\r\n**Customers who have upgraded to these versions should temporarily revert to the previous stable release while we prepare a corrected update.**\r\n\r\nA new patched release is expected by the end of the this month.\r\n\r\n**Further updates will be shared once the new version is available. We apologize for the inconvenience and appreciate your patience.**\r\n\r\n\r\n## 1.22.4 (February 18, 2026)\r\n\r\nSECURITY:\r\n* security: upgrade go version to 1.25.7 [[GH-23204](https://github.com/hashicorp/consul/issues/23204)]\r\n* dockerfile: the Consul build Go base image to `alpine3.23` [[GH-23194](https://github.com/hashicorp/consul/issues/23194)]\r\n* connect: Migrate to aws-sdk-go-v2 from aws-sdk-go (v1). Also updated consul-awsauth and go-secure-stdlib/awsutil dependencies to their v2 versions. [[GH-23109](https://github.com/hashicorp/consul/issues/23109)]\r\n* security: Configure HTTP server timeouts to prevent Slowloris denial-of-service attacks on agent HTTP endpoints and pprof endpoints. [[GH-22739](https://github.com/hashicorp/consul/issues/22739)]\r\n\r\nIMPROVEMENTS:\r\n* api-gateway: Fixed \"duplicate matcher\" errors in Envoy when using multiple file-system certificates on a single TLS listener. The certificates are now consolidated into a single filter chain, allowing Envoy to select the correct one. [[GH-23212](https://github.com/hashicorp/consul/issues/23212)]\r\n* agent: Fix vault provider failure when signing intermediate CA with isCA=true in CSR [[GH-23202](https://github.com/hashicorp/consul/issues/23202)]\r\n* cli: Added `--aws-iam-endpoint` flag to `consul login` command for AWS IAM auth method to support custom IAM endpoint configuration [[GH-23109](https://github.com/hashicorp/consul/issues/23109)]\r\n* api: Cancel context check for watches cache fetch to stop execution when manager deregisters the watch. [[GH-23157](https://github.com/hashicorp/consul/pull/23157)]\r\n\r\n","publishedAt":"2026-02-19T05:41:59.000Z","fetchedAt":"2026-04-08T00:01:05.496Z","url":"https://github.com/hashicorp/consul/releases/tag/v1.22.4","media":[],"coverageCount":0},{"id":"rel_vOnCpabVDJo5bp5tbyWas","version":"v1.22.3","type":"feature","title":"v1.22.3","summary":"## 1.22.3 (January 23, 2026)\r\n\r\nSECURITY:\r\n\r\n* Update the Consul Build Go base image to `alpine3.23.2` [[GH-23138](https://github.com/hashicorp/consul...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.22.3 (January 23, 2026)\r\n\r\nSECURITY:\r\n\r\n* Update the Consul Build Go base image to `alpine3.23.2` [[GH-23138](https://github.com/hashicorp/consul/issues/23138)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* api: Add `consul services imported-services` and new api(/v1/exported-services) command to list services imported by partitions within a local datacenter [[GH-12045](https://github.com/hashicorp/consul/issues/12045)]\r\n* connect: added ability to configure Virtual IP range for t-proxy with CIDRs [[GH-23085](https://github.com/hashicorp/consul/issues/23085)]\r\n\r\n","publishedAt":"2026-01-23T04:32:07.000Z","fetchedAt":"2026-04-08T00:01:05.496Z","url":"https://github.com/hashicorp/consul/releases/tag/v1.22.3","media":[],"coverageCount":0},{"id":"rel_WG0IWhlNq8qkGOwP-dnES","version":"v1.22.2","type":"feature","title":"v1.22.2","summary":"## 1.22.2 (December 15, 2025)\n\nSECURITY:\n\n* security: Upgrade golang to 1.25.4. [[GH-23029](https://github.com/hashicorp/consul/issues/23029)]\n* secur...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.22.2 (December 15, 2025)\n\nSECURITY:\n\n* security: Upgrade golang to 1.25.4. [[GH-23029](https://github.com/hashicorp/consul/issues/23029)]\n* security: upgrade internal packages of RHEL builds to include security fixes [[GH-23078](https://github.com/hashicorp/consul/issues/23078)]\n\nIMPROVEMENTS:\n\n* ui: upgraded Ember framework from v3.28 to v4.12, improving performance and stability. Upgrades multiple other packages which support Ember v4. [[GH-23070](https://github.com/hashicorp/consul/issues/23070)]\n\nBUG FIXES:\n\n* agent: fix bug prevents default TCP checks from being re-added on service reload when they were explicitly disabled or when custom checks were specified during initial registration. [[GH-23088](https://github.com/hashicorp/consul/issues/23088)]\n* audit-logging: (Enterprise only) Fixed JSON unmarshall error when array of obj is passed for auditReq body. [[GH-11546](https://github.com/hashicorp/consul/issues/11546)]\n* cli: Enhanced error messages in `consul config write` command to provide actionable guidance when config entries cannot be modified due to references by gateways or routers. [[GH-22921](https://github.com/hashicorp/consul/issues/22921)]\n* mesh: router + splitter + failover with retry now correctly failover for external services failover subsets through terminating gateways. [[GH-23092](https://github.com/hashicorp/consul/issues/23092)]\n\n","publishedAt":"2025-12-17T11:57:33.000Z","fetchedAt":"2026-04-08T00:01:05.496Z","url":"https://github.com/hashicorp/consul/releases/tag/v1.22.2","media":[],"coverageCount":0},{"id":"rel_pw5lmlSME0_wlaIUyVYTV","version":"ent-changelog-1.22.0","type":"feature","title":"v1.22.0 (Enterprise)","summary":"## 1.22.0+ent (October 24, 2025)\r\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached ...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.22.0+ent (October 24, 2025)\r\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\r\nSECURITY:\r\n\r\n* connect: Upgrade Consul's bundled Envoy version to 1.35.3 and remove support for 1.31.10. This update also includes a fix to prevent Envoy (v1.35+) startup failures by only configuring the TLS transport socket when the CA bundle is present. [[GH-22824](https://github.com/hashicorp/consul/issues/22824)]\r\n* security: Adding warning when remote/local script checks are enabled without enabling ACL's [[GH-22877](https://github.com/hashicorp/consul/issues/22877)]\r\n* security: Improved validation of the Content-Length header in the Consul KV endpoint to prevent potential denial of service attacks[CVE-2025-11374]() [[GH-22916](https://github.com/hashicorp/consul/issues/22916)]\r\n* security: adding a maximum Content-Length on the event endpoint to fix denial-of-service (DoS) attacks. This resolves [CVE-2025-11375](https://nvd.nist.gov/vuln/detail/CVE-2025-11375). [[GH-22836](https://github.com/hashicorp/consul/issues/22836)]\r\n* security: breaking change - adding a key name validation on the key/value endpoint along side with the DisableKVKeyValidation config to disable/enable it to fix path traversal attacks on misconfigured or missing ACL policies. [[GH-22850](https://github.com/hashicorp/consul/issues/22850)]\r\n\r\nFEATURES:\r\n\r\n* Added support to register a service in consul with multiple ports [[GH-22769](https://github.com/hashicorp/consul/issues/22769)]\r\n* agent: Added IsDualStack utility function to detect if the agent is configured for both IPv4 and IPv6 (dual-stack mode) based on its bind address retrieved from \"agent/self\" API. [[GH-22741](https://github.com/hashicorp/consul/issues/22741)]\r\n* install: Updated license information displayed during post-install\r\n* ipv6: addtition of ip6tables changes for ipv6 and dual stack support [[GH-22787](https://github.com/hashicorp/consul/issues/22787)]\r\n* oidc: add client authentication using JWT assertion and PKCE. default PKCE is enabled. [[GH-22732](https://github.com/hashicorp/consul/issues/22732)]\r\n\r\nIMPROVEMENTS:\r\n\r\n* security: Upgrade golang to 1.25.3. [[GH-22926](https://github.com/hashicorp/consul/issues/22926)]\r\n* ui: Fixes computed property override issues currently occurring and in some cases pre-emptively as this has been deprecated in ember v4 [[GH-22947](https://github.com/hashicorp/consul/issues/22947)]\r\n* ui: removes send action instances as part of https://deprecations.emberjs.com/id/ember-component-send-action/ [[GH-22938](https://github.com/hashicorp/consul/issues/22938)]\r\n* ui: replaced ember partials with components as an incremental step to upgrade to ember v4 [[GH-22888](https://github.com/hashicorp/consul/issues/22888)]\r\n* api: Added a new API (/v1/operator/utilization) to support enterprise API for Manual Snapshot Reporting [[GH-22837](https://github.com/hashicorp/consul/issues/22837)]\r\n* cmd: Added new subcommand `consul operator utilization [-today-only] [-message] [-y]` to generate a bundle with census utilization snapshot. Main flow is implemented in consul-enterprise\r\nhttp: Added a new API Handler for `/v1/operator/utilization`. Core functionality to be implemented in consul-enterprise\r\nagent: Always enabled census metrics collection with configurable option to export it to Hashicorp Reporting [[GH-22843](https://github.com/hashicorp/consul/issues/22843)]\r\n* cli: `snapshot agent` now supports authenticating to Azure Blob Storage using Azure Managed Service Identities (MSI). [[GH-11171](https://github.com/hashicorp/consul/issues/11171)]\r\n* command: connect envoy bootstrap defaults to 127.0.0.1 in IPv4-only environment and to ::1 in IPv6/DualStack environment. [[GH-22763](https://github.com/hashicorp/consul/issues/22763)]\r\n* connect: default upstream.local_bind_address to ::1 for IPv6 agent bind address [[GH-22773](https://github.com/hashicorp/consul/issues/22773)]\r\n* proxy: default proxy.local_service_address to ::1 for IPv6 agent bind address [[GH-22772](https://github.com/hashicorp/consul/issues/22772)]\r\n* ui: Improved accessibility features in the Consul UI to enhance usability for users with disabilities [[GH-22770](https://github.com/hashicorp/consul/issues/22770)]\r\n* ui: Replace yarn with pnpm for package management [[GH-22790](https://github.com/hashicorp/consul/issues/22790)]\r\n* ui: auth method config values were overflowing. This PR fixes the issue and adds word break for table elements with large content. [[GH-22813](https://github.com/hashicorp/consul/issues/22813)]\r\n\r\nBUG FIXES:\r\n\r\n* ui: Allow FQDN to be displayed in the Consul web interface. [[GH-22779](https://github.com/hashicorp/consul/issues/22779)]\r\n* ui: fixes the issue where namespaces where disappearing and Welcome to Namespace screen showed up after tab switching [[GH-22789](https://github.com/hashicorp/consul/issues/22789)]\r\n* ui: fixes the issue where when doing deletes of multiple tokens or policies, the three dots on the right hand side stops responding after the first delete. [[GH-22752](https://github.com/hashicorp/consul/issues/22752)]\r\n* cmd: Fix `consul operator utilization --help` to show only available options without extra parameters. [[GH-22912](https://github.com/hashicorp/consul/issues/22912)]\r\n\r\n","publishedAt":"2025-12-02T02:25:41.000Z","fetchedAt":"2026-04-08T00:01:05.769Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.22.0","media":[],"coverageCount":0},{"id":"rel_5W8xC9Me0HkJVwCskPCLg","version":"ent-changelog-1.20.13","type":"feature","title":"v1.20.13 (Enterprise)","summary":"## 1.20.13+ent (November 17, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.20.13+ent (November 17, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\nSECURITY:\n\n* security: Upgrade golang to 1.25.4. [[GH-23029](https://github.com/hashicorp/consul/issues/23029)]\n\nIMPROVEMENTS:\n\n* ui: Removed ember-route-action-helper and migrated all {{route-action}} usages to explicit route/controller logic. [[GH-23004](https://github.com/hashicorp/consul/issues/23004)]\n* ui: resolved multiple Ember deprecations:\n- Removed mutation-after-consumption warnings in Outlet by staging state updates outside the render pass\n- Replaced deprecated Route#replaceWith/transitionTo usage with RouterService in affected routes\n- Avoided mutating objects produced by {{hash}} (setting-on-hash) by switching to tracked POJOs [[GH-23010](https://github.com/hashicorp/consul/issues/23010)]\n\nBUG FIXES:\n\n* acl: fixed a bug where ACL policy replication in WANfed is impacted when primaryDC is inconsistent [[GH-22954](https://github.com/hashicorp/consul/issues/22954)]\n* xds: fix RBAC failure in upstream service when there are more than one downstream exported service with same name but different peer [[GH-23049](https://github.com/hashicorp/consul/issues/23049)]\n* xds: fix bug where Using replacePrefixMatch: \"/\" results in double slashes (//path) and Using replacePrefixMatch: \"\" does not strip the prefix at all (e.g., mapping /v1/dashboard → /dashboard) resulting in 301 and 404 errors respectively [[GH-23035](https://github.com/hashicorp/consul/issues/23035)]\n\n","publishedAt":"2025-12-02T02:25:37.000Z","fetchedAt":"2026-04-08T00:01:05.769Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.20.13","media":[],"coverageCount":0},{"id":"rel_VplgFOakDUcDPAiDunsA1","version":"ent-changelog-1.20.12","type":"feature","title":"v1.20.12 (Enterprise)","summary":"## 1.20.12 (October 30, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached sour...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.20.12 (October 30, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\nSECURITY:\n\n* security: Adding warning when remote/local script checks are enabled without enabling ACL's [[GH-22877](https://github.com/hashicorp/consul/issues/22877)]\n* security: Fixed proxied URL path validation to prevent path traversal. [[GH-22671](https://github.com/hashicorp/consul/issues/22671)]\n* security: Improved validation of the Content-Length header in the Consul KV endpoint to prevent potential denial of service attacks[CVE-2025-11374]() [[GH-22916](https://github.com/hashicorp/consul/issues/22916)]\n* security: adding a maximum Content-Length on the event endpoint to fix denial-of-service (DoS) attacks. This resolves [CVE-2025-11375](https://nvd.nist.gov/vuln/detail/CVE-2025-11375). [[GH-22836](https://github.com/hashicorp/consul/issues/22836)]\n* security: breaking change - adding a key name validation on the key/value endpoint along side with the DisableKVKeyValidation config to disable/enable it to fix path traversal attacks. This resolves [CVE-2025-11392](https://nvd.nist.gov/vuln/detail/CVE-2025-11392). [[GH-22850](https://github.com/hashicorp/consul/issues/22850)]\n\nFEATURES:\n\n* install: Updated license information displayed during post-install\n\nIMPROVEMENTS:\n\n* api: Added a new API (/v1/operator/utilization) to support enterprise API for Manual Snapshot Reporting [[GH-22837](https://github.com/hashicorp/consul/issues/22837)]\n* cmd: Added new subcommand `consul operator utilization [-today-only] [-message] [-y]` to generate a bundle with census utilization snapshot. Main flow is implemented in consul-enterprise\nhttp: Added a new API Handler for `/v1/operator/utilization`. Core functionality to be implemented in consul-enterprise\nagent: Always enabled census metrics collection with configurable option to export it to Hashicorp Reporting [[GH-22843](https://github.com/hashicorp/consul/issues/22843)]\n* security: Upgrade golang to 1.25.3. [[GH-22926](https://github.com/hashicorp/consul/issues/22926)]\n* ui: Fixes computed property override issues currently occurring and in some cases pre-emptively as this has been deprecated in ember v4 [[GH-22947](https://github.com/hashicorp/consul/issues/22947)]\n* ui: Improved accessibility features in the Consul UI to enhance usability for users with disabilities [[GH-22770](https://github.com/hashicorp/consul/issues/22770)]\n* ui: Replace yarn with pnpm for package management [[GH-22790](https://github.com/hashicorp/consul/issues/22790)]\n* ui: Replaced `reopen()` calls with direct property assignment and subclassing to resolve Ember component reopen deprecation warnings [[GH-22971](https://github.com/hashicorp/consul/issues/22971)]\n* ui: auth method config values were overflowing. This PR fixes the issue and adds word break for table elements with large content. [[GH-22813](https://github.com/hashicorp/consul/issues/22813)]\n* ui: removed deprecated Route#renderTemplate usage by introducing DebugLayout component and controller-based conditional rendering for docs routes [[GH-22978](https://github.com/hashicorp/consul/issues/22978)]\n* ui: removes send action instances as part of https://deprecations.emberjs.com/id/ember-component-send-action/ [[GH-22938](https://github.com/hashicorp/consul/issues/22938)]\n* ui: replaced ember partials with components as an incremental step to upgrade to ember v4 [[GH-22888](https://github.com/hashicorp/consul/issues/22888)]\n\nBUG FIXES:\n\n* cmd: Fix `consul operator utilization --help` to show only available options without extra parameters. [[GH-22912](https://github.com/hashicorp/consul/issues/22912)]\n* ui: fixes the issue where namespaces where disappearing and Welcome to Namespace screen showed up after tab switching [[GH-22789](https://github.com/hashicorp/consul/issues/22789)]\n* ui: fixes the issue where when doing deletes of multiple tokens or policies, the three dots on the right hand side stops responding after the first delete. [[GH-22752](https://github.com/hashicorp/consul/issues/22752)]","publishedAt":"2025-12-02T02:25:33.000Z","fetchedAt":"2026-04-08T00:01:05.769Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.20.12","media":[],"coverageCount":0},{"id":"rel_QF10xw_I96aytCT7hKBYm","version":"ent-changelog-1.20.11","type":"feature","title":"v1.20.11 (Enterprise)","summary":"## 1.20.11+ent (September 21, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attache...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.20.11+ent (September 21, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\nSECURITY:\n\n* Migrate transitive dependency from archived `mitchellh/mapstructure` to `go-viper/mapstructure` to v2 to address [CVE-2025-52893](https://www.cve.org/CVERecord?id=CVE-2025-52893). [[GH-22581](https://github.com/hashicorp/consul/issues/22581)]\n* agent: Add the KV Validations to block path traversal allowing access to unauthorized endpoints. [[GH-22682](https://github.com/hashicorp/consul/issues/22682)]\n* agent: Fix a security vulnerability to filter out anonymous tokens along with empty tokens when setting the Results-Filtered-By-ACLs header [[GH-22534](https://github.com/hashicorp/consul/issues/22534)]\n* agent: Fix a security vulnerability where the attacker could read agent’s TLS certificate and private key by using the group ID that the Consul agent runs as. [[GH-22626](https://github.com/hashicorp/consul/issues/22626)]\n* api: add charset in all applicable content-types. [[GH-22598](https://github.com/hashicorp/consul/issues/22598)]\n* connect: Upgrade envoy version to 1.33.9 [[GH-11329](https://github.com/hashicorp/consul/issues/11329)]\n* security: Fix GHSA-65rg-554r-9j5x (CVE-2024-48908) by upgrading lycheeverse/lychee-action. [[GH-22667](https://github.com/hashicorp/consul/issues/22667)]\n* security: Fix a security vulnerability where the attacker could bypass authentication by passing url params as there was no validation on them. [[GH-22612](https://github.com/hashicorp/consul/issues/22612)]\n* security: perform constant time compare for sensitive values. [[GH-22537](https://github.com/hashicorp/consul/issues/22537)]\n* security: upgrade go version to 1.25.0 [[GH-22652](https://github.com/hashicorp/consul/issues/22652)]\n* security:: **(Enterprise only)**  fix nil pointer dereference.\n* security:: **(Enterprise only)**  fix potential race condition in partition CRUD.\n* security:: **(Enterprise only)**  perform constant time compare for sensitive values.\n\nFEATURES:\n\n* config: Add new parameter `max_request_headers_kb` to configure maximum header size for requests from downstream to upstream [[GH-22604](https://github.com/hashicorp/consul/issues/22604)]\n* config: Handle a new parameter `max_request_headers_kb` to configure maximum header size for requests from downstream to upstream in API Gateway config and proxy-defaults [[GH-22679](https://github.com/hashicorp/consul/issues/22679)]\n* config: Handle a new parameter `max_request_headers_kb` to configure maximum header size for requests from downstream to upstream in Mesh Gateway via service-defaults and proxy-defaults [[GH-22722](https://github.com/hashicorp/consul/issues/22722)]\n* config: Handle a new parameter `max_request_headers_kb` to configure maximum header size for requests from downstream to upstream in Terminating Gateway service-defaults and proxy-defaults [[GH-22680](https://github.com/hashicorp/consul/issues/22680)]\n\nBUG FIXES:\n\n* agent: Don't show admin partition during errors [[GH-11154](https://github.com/hashicorp/consul/issues/11154)]\n\n","publishedAt":"2025-12-02T02:25:29.000Z","fetchedAt":"2026-04-08T00:01:06.043Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.20.11","media":[],"coverageCount":0},{"id":"rel_lpBLQah5FlIkgbWmyypE7","version":"ent-changelog-1.20.10","type":"feature","title":"v1.20.10 (Enterprise)","summary":"## 1.20.10 Enterprise (August 13, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The att...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.20.10 Enterprise (August 13, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\nSECURITY:\n\n* security: Update Go to 1.23.12 to address CVE-2025-47906 [[GH-22547](https://github.com/hashicorp/consul/issues/22547)]\n\nIMPROVEMENTS:\n\n* ui: Replaced internal code editor with HDS (HashiCorp Design System) code editor and code block components for improved accessibility and maintainability across the Consul UI. [[GH-22513](https://github.com/hashicorp/consul/issues/22513)]\n\nBUG FIXES:\n\n* cli: capture pprof when ACL is enabled and a token with operator:read is used, even if enable_debug config is not explicitly set. [[GH-22552](https://github.com/hashicorp/consul/issues/22552)]","publishedAt":"2025-12-02T02:25:25.000Z","fetchedAt":"2026-04-08T00:01:06.043Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.20.10","media":[],"coverageCount":0},{"id":"rel_755_a-nj1-y76_PnZZxtM","version":"ent-changelog-1.20.9","type":"feature","title":"v1.20.9 (Enterprise)","summary":"## 1.20.9 Enterprise (July 28, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attach...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.20.9 Enterprise (July 28, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\nSECURITY:\n\n* Update `github.com/containerd/containerd` to 1.7.3  [[GH-10888](https://github.com/hashicorp/consul-enterprise/issues/10888)]\n* Bump Dockerfile base image to `alpine:3.22`. [[GH-10872](https://github.com/hashicorp/consul-enterprise/issues/10872)]\n* build(deps): bump golang.org/x/sync from 0.12.0 to 0.15.0 [[GH-10787](https://github.com/hashicorp/consul-enterprise/issues/10787)]","publishedAt":"2025-12-02T02:25:20.000Z","fetchedAt":"2026-04-08T00:01:05.769Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.20.9","media":[],"coverageCount":0},{"id":"rel_q4KdZGrR5poNeTU2I-EF9","version":"ent-changelog-1.20.8","type":"feature","title":"v1.20.8 (Enterprise)","summary":"## 1.20.8 Enterprise (June 18, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attach...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.20.8 Enterprise (June 18, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\nSECURITY:\n\n* security: Upgrade UBI base image version to address CVE\n[CVE-2025-4802](https://access.redhat.com/security/cve/cve-2025-4802)\n[CVE-2024-40896](https://access.redhat.com/security/cve/cve-2024-40896)\n[CVE-2024-12243](https://nvd.nist.gov/vuln/detail/CVE-2024-12243)\n[CVE-2025-24528](https://access.redhat.com/security/cve/cve-2025-24528)\n[CVE-2025-3277](https://access.redhat.com/security/cve/cve-2025-3277)\n[CVE-2024-12133](https://access.redhat.com/security/cve/cve-2024-12133)\n[CVE-2024-57970](https://access.redhat.com/security/cve/cve-2024-57970)\n[CVE-2025-31115](https://access.redhat.com/security/cve/cve-2025-31115) [[GH-22409](https://github.com/hashicorp/consul/issues/22409)]\n* cli: update tls ca and cert create to reduce excessive file perms for generated public files [[GH-22286](https://github.com/hashicorp/consul/issues/22286)]\n* connect: Added non default namespace and partition checks to ConnectCA CSR requests. [[GH-22376](https://github.com/hashicorp/consul/issues/22376)]\n* security: Upgrade Go to 1.23.10. [[GH-22412](https://github.com/hashicorp/consul/issues/22412)]\n\nIMPROVEMENTS:\n\n* config: Warn about invalid characters in `datacenter` resulting in non-generation of X.509 certificates when using external CA for agent TLS communication. [[GH-22382](https://github.com/hashicorp/consul/issues/22382)]\n\nBUG FIXES:\n\n* http: return a clear error when both Service.Service and Service.ID are missing during catalog registration [[GH-22381](https://github.com/hashicorp/consul/issues/22381)]\n* license: (Enterprise only) Fixed issue where usage metrics are not written to the snapshot to export the license data. [[GH-10668](https://github.com/hashicorp/consul/issues/10668)]","publishedAt":"2025-12-02T02:25:17.000Z","fetchedAt":"2026-04-08T00:01:05.769Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.20.8","media":[],"coverageCount":0},{"id":"rel_jEDBH_FFfrOomz4GvXLT4","version":"ent-changelog-1.20.0","type":"feature","title":"v1.20.0 (Enterprise)","summary":"## 1.20.0 (October 14, 2024)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached sourc...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.20.0 (October 14, 2024)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\nSECURITY:\n\n* Explicitly set 'Content-Type' header to mitigate XSS vulnerability. [[GH-21704](https://github.com/hashicorp/consul/issues/21704)]\n* Implement HTML sanitization for user-generated content to prevent XSS attacks in the UI. [[GH-21711](https://github.com/hashicorp/consul/issues/21711)]\n* UI: Remove codemirror linting due to package dependency [[GH-21726](https://github.com/hashicorp/consul/issues/21726)]\n* Upgrade Go to use 1.22.7. This addresses CVE \n[CVE-2024-34155](https://nvd.nist.gov/vuln/detail/CVE-2024-34155) [[GH-21705](https://github.com/hashicorp/consul/issues/21705)]\n* Upgrade to support aws/aws-sdk-go `v1.55.5 or higher`. This resolves CVEs\n[CVE-2020-8911](https://nvd.nist.gov/vuln/detail/cve-2020-8911) and \n[CVE-2020-8912](https://nvd.nist.gov/vuln/detail/cve-2020-8912). [[GH-21684](https://github.com/hashicorp/consul/issues/21684)]\n* ui: Pin a newer resolution of Braces [[GH-21710](https://github.com/hashicorp/consul/issues/21710)]\n* ui: Pin a newer resolution of Codemirror [[GH-21715](https://github.com/hashicorp/consul/issues/21715)]\n* ui: Pin a newer resolution of Markdown-it [[GH-21717](https://github.com/hashicorp/consul/issues/21717)]\n* ui: Pin a newer resolution of ansi-html [[GH-21735](https://github.com/hashicorp/consul/issues/21735)]\n\nFEATURES:\n\n* grafana: added the dashboards service-to-service dashboard, service dashboard, and consul dataplane dashboard [[GH-21806](https://github.com/hashicorp/consul/issues/21806)]\n* server: remove v2 tenancy, catalog, and mesh experiments [[GH-21592](https://github.com/hashicorp/consul/issues/21592)]\n\nIMPROVEMENTS:\n\n* security: upgrade ubi base image to 9.4 [[GH-21750](https://github.com/hashicorp/consul/issues/21750)]\n* connect: Add Envoy 1.31 and 1.30 to support matrix [[GH-21616](https://github.com/hashicorp/consul/issues/21616)]\n\nBUG FIXES:\n\n* jwt-provider: change dns lookup family from the default of AUTO which would prefer ipv6 to ALL if LOGICAL_DNS is used or PREFER_IPV4 if STRICT_DNS is used to gracefully handle transitions to ipv6. [[GH-21703](https://github.com/hashicorp/consul/issues/21703)]","publishedAt":"2025-12-02T02:25:13.000Z","fetchedAt":"2026-04-08T00:01:06.043Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.20.0","media":[],"coverageCount":0},{"id":"rel_tBq6AfiQDbB_-OZtkAcXE","version":"ent-changelog-1.19.13","type":"feature","title":"v1.19.13 (Enterprise)","summary":"## 1.19.13+ent (September 21, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attache...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 1.19.13+ent (September 21, 2025)\nThis release is created to share the Consul Enterprise changelog and notify consumers of availability. The attached source and assets do not include Consul Enterprise code and should not be used in place of official Docker images or binaries.\n\nSECURITY:\n\n* Migrate transitive dependency from archived `mitchellh/mapstructure` to `go-viper/mapstructure` to v2 to address [CVE-2025-52893](https://www.cve.org/CVERecord?id=CVE-2025-52893). [[GH-22581](https://github.com/hashicorp/consul/issues/22581)]\n* agent: Add the KV Validations to block path traversal allowing access to unauthorized endpoints. [[GH-22682](https://github.com/hashicorp/consul/issues/22682)]\n* agent: Fix a security vulnerability to filter out anonymous tokens along with empty tokens when setting the Results-Filtered-By-ACLs header [[GH-22534](https://github.com/hashicorp/consul/issues/22534)]\n* agent: Fix a security vulnerability where the attacker could read agent’s TLS certificate and private key by using the group ID that the Consul agent runs as. [[GH-22626](https://github.com/hashicorp/consul/issues/22626)]\n* api: add charset in all applicable content-types. [[GH-22598](https://github.com/hashicorp/consul/issues/22598)]\n* connect: Upgrade envoy version to 1.32.12 [[GH-11331](https://github.com/hashicorp/consul/issues/11331)]\n* security: Fix GHSA-65rg-554r-9j5x (CVE-2024-48908) by upgrading lycheeverse/lychee-action. [[GH-22667](https://github.com/hashicorp/consul/issues/22667)]\n* security: Fix a security vulnerability where the attacker could bypass authentication by passing url params as there was no validation on them. [[GH-22612](https://github.com/hashicorp/consul/issues/22612)]\n* security: perform constant time compare for sensitive values. [[GH-22537](https://github.com/hashicorp/consul/issues/22537)]\n* security: upgrade go version to 1.25.0 [[GH-22652](https://github.com/hashicorp/consul/issues/22652)]\n* security:: **(Enterprise only)**  fix nil pointer dereference.\n* security:: **(Enterprise only)**  fix potential race condition in partition CRUD.\n* security:: **(Enterprise only)**  perform constant time compare for sensitive values.\n\nFEATURES:\n\n* config: Add new parameter `max_request_headers_kb` to configure maximum header size for requests from downstream to upstream [[GH-22604](https://github.com/hashicorp/consul/issues/22604)]\n* config: Handle a new parameter `max_request_headers_kb` to configure maximum header size for requests from downstream to upstream in API Gateway config and proxy-defaults [[GH-22679](https://github.com/hashicorp/consul/issues/22679)]\n* config: Handle a new parameter `max_request_headers_kb` to configure maximum header size for requests from downstream to upstream in Mesh Gateway via service-defaults and proxy-defaults [[GH-22722](https://github.com/hashicorp/consul/issues/22722)]\n* config: Handle a new parameter `max_request_headers_kb` to configure maximum header size for requests from downstream to upstream in Terminating Gateway service-defaults and proxy-defaults [[GH-22680](https://github.com/hashicorp/consul/issues/22680)]\n\nBUG FIXES:\n\n* agent: Don't show admin partition during errors [[GH-11154](https://github.com/hashicorp/consul/issues/11154)]\n\n","publishedAt":"2025-12-02T02:25:09.000Z","fetchedAt":"2026-04-08T00:01:06.043Z","url":"https://github.com/hashicorp/consul/releases/tag/ent-changelog-1.19.13","media":[],"coverageCount":0}],"pagination":{"nextCursor":"2025-12-02T02:25:09.000Z|2026-04-08T00:01:06.043Z|rel_tBq6AfiQDbB_-OZtkAcXE","limit":20},"summaries":{"rolling":null,"monthly":[]}}