StackWatch

Consul

tool22 releases · 12 support lines

Support lines

LTS status and end of life
LineLatestStatusEnd of life
2.02.0.3supported
1.221.22.7supported
1.211.21.5supported
1.201.20.6eol24 May 2026
1.191.19.2eol27 Oct 2025
1.181.18.2eol6 May 2025
1.171.17.4eol14 Oct 2024
1.161.16.7eol12 Jun 2024
1.151.15.11eol27 Feb 2024
1.141.14.11eol3 Nov 2023
1.131.13.9eol26 Jun 2023
1.121.12.9eol23 Feb 2023

Releases

newest first
Consulv2.0.35d agosecurity
  • Multiple security vulnerabilities fixed including DoS attacks via unbounded caching, nil-pointer panics, path normalization bypass, and unauthenticated JSON decoder attacks
  • New gRPC connection limiter configuration option (limits.grpc_max_conns_per_client) to prevent connection exhaustion attacks
  • API Gateway now correctly handles service-router configurations that compose routes across different services, namespaces, or partitions
  • New XDS configuration options for controlling server response headers on API Gateway HTTP listeners
advisories
changelog ↗
Consulv2.0.224d agosecurity
  • Alpine base image upgraded to address security vulnerabilities
  • Serf and Memberlist dependencies updated to latest versions
  • XDS now returns errors when L4 intention filters or mTLS cannot be enforced on inbound public listeners
  • Fixed client certificate SDS block emission to only occur when both CertFile and KeyFile are configured
to upgrade

If using consul OSS version with consul-k8s, use Helm Chart version '2.0.2-oss' instead of '2.0.2' to resolve the missing RouteExtProc CRD issue.

changelog ↗
Consulv2.0.12mo agobreaking
  • Security: Go upgraded to 1.26.4 and Envoy versions updated (1.37.4, 1.36.8, 1.35.12 supported; 1.38.2 added; 1.34.14 removed) to address vulnerabilities
  • Fixed a bug where renaming a server could cause leader eviction and HTTP 500 errors on follower RPCs
  • Fixed a security issue where x-forwarded-client-cert headers were not stripped from inbound HTTP requests
  • Auth method TokenNameFormat field now accepts OIDC and JWT claim mapping values
what breaks

Envoy version 1.34.14 is no longer supported and has been removed.

to upgrade

Upgrade Go to version 1.26.4. Update Envoy to a supported version (1.35.12, 1.36.8, 1.37.4, or 1.38.2); version 1.34.14 is no longer supported.

changelog ↗
Consulv2.0.02mo agosecurity
  • Security patches for Envoy, Go runtime, curl, and UBI base images address multiple CVEs
  • HTTP request path normalization on API Gateway and terminating gateway prevents L7 intention RBAC bypass (CVE-2024-10005)
  • New enterprise features including global rate limiting, multi-port service support, and Cyberark WIM CA provider
  • API Gateway now supports SDS certificates, gateway-level upstream limits, and improved XDS generation for peered deployments
changelog ↗

← back to the digest