PT-2026-21259 · Unknown+1 · Consul-K8S-Fips+1

Published

2026-01-30

·

Updated

2026-02-26

·

CVE-2025-47903

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions consul-k8s-fips (affected versions not specified)
Description The consul-k8s-fips package is affected by multiple security issues. The net/http package does not correctly handle line terminators in chunked data, potentially leading to issues. Additionally, certificate chain validation does not properly restrict wildcard SANs when an excluded subdomain constraint is present. The package also includes Moby, an open source container framework.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CLEANSTART-2026-BQ46815
CLEANSTART-2026-BT39952
CLEANSTART-2026-DV06422
CLEANSTART-2026-IA37596
CLEANSTART-2026-KK99760
CLEANSTART-2026-ME47927
CLEANSTART-2026-PA85871
CLEANSTART-2026-SO16176
CLEANSTART-2026-VU62737
CVE-2025-47903

Affected Products

Moby
Consul-K8S-Fips