NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #77 by repository stars
Last release 2 days ago
06 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
12404 releases · first in 2013
security: update google.golang.org/grpc to fix CVE-2026-33186 [GH-23379]
SECURITY:
IMPROVEMENTS:
BUG FIXES:
replacePrefixMatch is not configured [GH-23390]One column per quarter.
security: update google.golang.org/grpc to fix CVE-2026-33186 [GH-23379]
SECURITY:
IMPROVEMENTS:
security: upgrade go version to 1.25.7 [GH-23204]
SECURITY:
alpine3.23 [GH-23194]IMPROVEMENTS:
--aws-iam-endpoint flag to consul login command for AWS IAM auth method to support custom IAM endpoint configuration [GH-23109]WITHDRAWN - This release has been retracted from public distribution due to critical issues. Please use 1.22.5 or remain on 1.22.3.
WITHDRAWN - This release has been retracted from public distribution due to critical issues. Please use 1.22.5 or remain on 1.22.3.
Update the Consul Build Go base image to alpine3.23.2 [GH-23138]
Nothing published for this version
ui: Replaced reopen() calls with direct property assignment and subclassing to resolve Ember component reopen deprecation warnings [GH-22971]
SECURITY:
golang.org/x/crypto from v0.42.0 to v0.44.0. This resolves GO-2025-4116IMPROVEMENTS:
reopen() calls with direct property assignment and subclassing to resolve Ember component reopen deprecation warnings [GH-22971]BUG FIXES:
…to prevent potential denial of service attacksCVE-2025-11374 [GH-22916]
SECURITY:
FEATURES:
IMPROVEMENTS:
consul operator utilization [-today-only] [-message] [-y] to generate a bundle with census utilization snapshot. Main flow is implemented in consul-enterprise
http: Added a new API Handler for /v1/operator/utilization. Core functionality to be implemented in consul-enterprise
agent: Always enabled census metrics collection with configurable option to export it to Hashicorp Reporting [GH-22843]snapshot agent now supports authenticating to Azure Blob Storage using Azure Managed Service Identities (MSI). [GH-11171]BUG FIXES:
consul operator utilization --help to show only available options without extra parameters. [GH-22912]…to prevent potential denial of service attacksCVE-2025-11374 [GH-22916]
SECURITY:
BUG FIXES:
consul operator utilization --help to show only available options without extra parameters. [GH-22912]connect: Upgrade Consul's bundled Envoy version to 1.35.3 and remove support for 1.31.10. This update also includes a fix to prevent Envoy (v1.35+) st
SECURITY:
FEATURES:
IMPROVEMENTS:
consul operator utilization [-today-only] [-message] [-y] to generate a bundle with census utilization snapshot. Main flow is implemented in consul-enterprise
http: Added a new API Handler for /v1/operator/utilization. Core functionality to be implemented in consul-enterprise
agent: Always enabled census metrics collection with configurable option to export it to Hashicorp Reporting [GH-22843]snapshot agent now supports authenticating to Azure Blob Storage using Azure Managed Service Identities (MSI). [GH-11171]BUG FIXES:
Migrate transitive dependency from archived mitchellh/mapstructure to go-viper/mapstructure to v2 to address CVE-2025-52893. [GH-22581]
SECURITY:
mitchellh/mapstructure to go-viper/mapstructure to v2 to address CVE-2025-52893. [GH-22581]FEATURES:
max_request_headers_kb to configure maximum header size for requests from downstream to upstream [GH-22604]max_request_headers_kb to configure maximum header size for requests from downstream to upstream in API Gateway config and proxy-defaults [GH-22679]max_request_headers_kb to configure maximum header size for requests from downstream to upstream in Mesh Gateway via service-defaults and proxy-defaults [GH-22722]max_request_headers_kb to configure maximum header size for requests from downstream to upstream in Terminating Gateway service-defaults and proxy-defaults [GH-22680]IMPROVEMENTS:
BUG FIXES:
security: Update Go to 1.23.12 to address CVE-2025-47906 [GH-22547]
SECURITY:
IMPROVEMENTS:
BUG FIXES:
ui: Improved display and handling of IPv6 addresses for better readability and usability in the Consul web interface. [GH-22468]
IMPROVEMENTS:
BUG FIXES:
security: Upgrade UBI base image version to address CVE CVE-2025-4802 CVE-2024-40896 CVE-2024-12243 CVE-2025-24528 CVE-2025-3277 CVE-2024-12133 CVE-20…
SECURITY:
IMPROVEMENTS:
datacenter resulting in non-generation of X.509 certificates when using external CA for agent TLS communication. [GH-22382]BUG FIXES:
xds: Extend LUA Script support for API Gateway [GH-22321]
FEATURES:
IMPROVEMENTS:
Enhancement: Added support for Consul Session to update the state of a Health Check, allowing for more dynamic and responsive health monitoring within
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Upgrade Go to use v1.22.11 and bump Go X-Repositories to latest. This addresses CVE CVE-2024-45341 and CVE-2024-45336 [GH-22084]
SECURITY:
IMPROVEMENTS:
BUG FIXES:
Update registry.access.redhat.com/ubi9-minimal image to 9.5 to address CVE-2024-3596,CVE-2024-2511,CVE-2024-26458. [GH-22011]
SECURITY:
github.com/golang-jwt/jwt/v4 to v4.5.1 to address GHSA-29wx-vh33-7x7r. [GH-21951]golang.org/x/crypto to v0.31.0 to address GO-2024-3321. [GH-22001]golang.org/x/net to v0.33.0 to address GO-2024-3333. [GH-22021]registry.access.redhat.com/ubi9-minimal image to 9.5 to address CVE-2024-3596,CVE-2024-2511,CVE-2024-26458. [GH-22011]mesh: Enable Envoy HttpConnectionManager.normalize_path by default on inbound traffic to mesh proxies. This resolves CVE-2024-10005. [GH-21816]
BREAKING CHANGES:
HttpConnectionManager.normalize_path by default on inbound traffic to mesh proxies. This resolves CVE-2024-10005. [GH-21816]SECURITY:
contains and ignoreCase to L7 Intentions HTTP header matching criteria to support configuration resilient to variable casing and multiple values. This resolves CVE-2024-10006. [GH-21816]http.incoming.requestNormalization to Mesh configuration entry to support inbound service traffic request normalization. This resolves CVE-2024-10005 and CVE-2024-10006. [GH-21816]IMPROVEMENTS:
Explicitly set 'Content-Type' header to mitigate XSS vulnerability. [GH-21704]
SECURITY:
v1.55.5 or higher. This resolves CVEs
CVE-2020-8911 and
CVE-2020-8912. [GH-21684]FEATURES:
IMPROVEMENTS:
BUG FIXES:
Nothing published for this version
Explicitly set 'Content-Type' header to mitigate XSS vulnerability. [GH-21704]
SECURITY:
v1.55.5 or higher. This resolves CVEs
CVE-2020-8911 and
CVE-2020-8912. [GH-21684]FEATURES:
IMPROVEMENTS:
BUG FIXES:
ui: Upgrade modules with d3-color as a dependency to address denial of service issue in d3-color < 3.1.0 [GH-21588]
SECURITY:
IMPROVEMENTS:
BUG FIXES:
Upgrade envoy module dependencies to version 1.27.7, 1.28.5 and 1.29.7 or higher to resolve CVE-2024-39305 [GH-21524]
SECURITY:
IMPROVEMENTS:
BUG FIXES:
tag.name.service.consul, were being disregarded. [GH-21361]Upgrade to support Envoy 1.27.5 and 1.28.3. This resolves CVE CVE-2024-32475 (auto_sni). [GH-21017]
BREAKING CHANGES:
consul element in the metric name have been removed. Please use the same metric without the second consul instead. As an example instead of consul.consul.state.config_entries use consul.state.config_entries [GH-20674]SECURITY:
1.27.5 and 1.28.3. This resolves CVE
CVE-2024-32475 (auto_sni). [GH-21017]v0.18.7 or higher. This resolves CVE
CVE-2020-8559. [GH-21017]FEATURES:
v1dns in the experiments agent config to disable.
The legacy server will be removed in a future release of Consul.
See the Consul 1.19.x Release Notes for removed DNS features. [GH-20715]IMPROVEMENTS:
github.com/envoyproxy/go-control-plane to 0.12.0. [GH-20973]consul-dataplane now accepts partition, namespace, token as metadata to default those query parameters.
consul-dataplane v1.5+ will send this information automatically. [GH-20899]consul snapshot decode CLI command to output a JSON object stream of all the snapshots data. [GH-20824]telemetry.disable_per_tenancy_usage_metrics in agent configuration to disable setting tenancy labels on usage metrics. This significantly decreases CPU utilization in clusters with many admin partitions or namespaces.DEPRECATIONS:
local_storage, aws_storage, azure_blob_storage, and google_storage in snapshot agent configuration files are now deprecated. Use the backup_destinations config object instead.BUG FIXES:
Update vault/api to v1.12.2 to address CVE-2024-28180 (removes indirect dependency on impacted go-jose.v2) [GH-20910]
Enterprise LTS: Consul Enterprise 1.18 is a Long-Term Support (LTS) release.
SECURITY:
alpine:3.19. [GH-20897]vault/api to v1.12.2 to address CVE-2024-28180
(removes indirect dependency on impacted go-jose.v2) [GH-20910]1.26.8, 1.27.4, 1.27.5, 1.28.2 and 1.28.3. This resolves CVEs
CVE-2024-27919 (http2). [GH-20956] and CVE-2024-32475 (auto_sni). [GH-21030]v0.18.7 or higher. This resolves CVE
CVE-2020-8559. [GH-21034]1.21.9. This resolves CVE
CVE-2023-45288 (http2). [GH-20956]v0.24.0. This resolves CVE
CVE-2023-45288 (x/net). [GH-20956]IMPROVEMENTS:
BUG FIXES:
DefaultForFailover.
DNS requests against sameness groups without this field set will now error as intended.Update google.golang.org/protobuf to v1.33.0 to address CVE-2024-24786. [GH-20801]
Enterprise LTS: Consul Enterprise 1.18 is a Long-Term Support (LTS) release.
BREAKING CHANGES:
SECURITY:
google.golang.org/protobuf to v1.33.0 to address CVE-2024-24786. [GH-20801]alpine3.19. This resolves CVEs
CVE-2023-52425
CVE-2023-52426 [GH-20812]1.21.8. This resolves CVEs
CVE-2024-24783 (crypto/x509).
CVE-2023-45290 (net/http).
CVE-2023-45289 (net/http, net/http/cookiejar).
CVE-2024-24785 (html/template).
CVE-2024-24784 (net/mail). [GH-20812]IMPROVEMENTS:
backup_destinations config file object.BUG FIXES:
Update golang.org/x/crypto to v0.17.0 to address CVE-2023-48795. [GH-20023]
BREAKING CHANGES:
telemetry.disable_hostname when determining whether to prefix gauge-type metrics with the hostname of the Consul agent. Previously, if only the default metric sink was enabled, this configuration was ignored and always treated as true, even though its default value is false. [GH-20312]SECURITY:
golang.org/x/crypto to v0.17.0 to address CVE-2023-48795. [GH-20023]FEATURES:
v2dns in the experiments agent config to enable.
It will automatically be enabled when using the resource-apis (Catalog v2) experiment.
The new DNS implementation will be the default in Consul 1.19.
See the Consul 1.18.x Release Notes for deprecated DNS features. [GH-20643]IMPROVEMENTS:
envoy.config.core.v3.HeaderValueOption.append. [GH-20078]envoy.config.route.v3.HeaderMatcher.safe_regex_match and envoy.type.matcher.v3.RegexMatcher.google_re2. [GH-20013]BUG FIXES:
Nothing published for this version
Nothing published for this version
Update google.golang.org/protobuf to v1.33.0 to address CVE-2024-24786. [GH-20801]
SECURITY:
google.golang.org/protobuf to v1.33.0 to address CVE-2024-24786. [GH-20801]alpine3.19. This resolves CVEs
CVE-2023-52425
CVE-2023-52426 [GH-20812]1.21.8. This resolves CVEs
CVE-2024-24783 (crypto/x509).
CVE-2023-45290 (net/http).
CVE-2023-45289 (net/http, net/http/cookiejar).
CVE-2024-24785 (html/template).
CVE-2024-24784 (net/mail). [GH-20812]IMPROVEMENTS:
backup_destinations config file object.BUG FIXES:
mesh: Update Envoy versions to 1.27.3 and 1.26.7 to address CVE-2024-23324, CVE-2024-23325, CVE-2024-23322, CVE-2024-23323, CVE-2024-23327, and CVE-20…
SECURITY:
FEATURES:
exported-services to list all services exported and their consumers. Refer to the CLI docs for more information. [GH-20331]IMPROVEMENTS:
Internal.ServiceDump when mesh gateway is not used. [GH-20168]Internal.ServiceDump watch from proxycfg [GH-20168]CaseInsensitive flag to service-routers that allows paths and path prefixes to ignore URL upper and lower casing. [GH-19647]BUG FIXES:
http protocol fails with a protocol-mismatch error. [GH-20481]connect: Remove usage of deprecated Envoy field match_subject_alt_names in favor of match_typed_subject_alt_names. [GH-19954]
KNOWN ISSUES:
SECURITY:
ubi9-minimal:9.3 as the base image. [GH-20014]IMPROVEMENTS:
match_subject_alt_names in favor of match_typed_subject_alt_names. [GH-19954]envoy.config.router.v3.WeightedCluster.total_weight. [GH-20011]envoy.config.cluster.v3.Cluster.http_protocol_options [GH-20010]envoy.config.cluster.v3.Cluster.http2_protocol_options, envoy.config.bootstrap.v3.Admin.access_log_path [GH-19940]envoy.extensions.filters.http.lua.v3.Lua.inline_code [GH-20012]DEPRECATIONS:
-admin-access-log-path flag from consul connect envoy command in favor of: -admin-access-log-config. [GH-19943]BUG FIXES:
Upgrade to use Go 1.20.12. This resolves CVEs CVE-2023-45283: (path/filepath) recognize \??\ as a Root Local Device path prefix (Windows) CVE-2023-452…
SECURITY:
github.com/golang-jwt/jwt/v4 to v4.5.0 to address PRISMA-2022-0270. [GH-19705]path/filepath) recognize ??\ as a Root Local Device path prefix (Windows)
CVE-2023-45284: recognize device names with trailing spaces and superscripts (Windows)
CVE-2023-39326: (net/http) limit chunked data overhead
CVE-2023-45285: (cmd/go) go get may unexpectedly fallback to insecure git [GH-19840]FEATURES:
peering exported-services to list services exported to a peer . Refer to the CLI docs for more information. [GH-19821]IMPROVEMENTS:
stats_flush_interval to 60 seconds when using the Consul Telemetry Collector, unless custom stats sink are present or an explicit flush interval is configured. [GH-19663]BUG FIXES:
xds_fetch_timeout_ms option to proxy registrations that allows users to prevent endpoints from dropping when they have proxies with a large number of upstreams. [GH-19871]Update golang.org/x/net to v0.17.0 to address CVE-2023-39325 / CVE-2023-44487(x/net/http2). [GH-19225]
BREAKING CHANGES:
DEPRECATIONS:
-admin-access-log-path flag from consul connect envoy command in favor of: -admin-access-log-config. [GH-15946]SECURITY:
golang.org/x/net to v0.17.0 to address CVE-2023-39325
/ CVE-2023-44487(x/net/http2). [GH-19225]net/http). [GH-19225]google.golang.org/grpc to 1.56.3.
This resolves vulnerability CVE-2023-44487. [GH-19414]FEATURE PREVIEW: Catalog v2
This release provides the ability to preview Consul's v2 Catalog and Resource API if enabled. The new model supports multi-port application deployments with only a single Envoy proxy. Note that the v1 and v2 catalogs are not cross compatible, and not all Consul features are available within this v2 feature preview. See the v2 Catalog and Resource API documentation for more information. The v2 Catalog and Resources API should be considered a feature preview within this release and should not be used in production environments.
Limitations
Significant Pull Requests
FEATURES:
acl.tokens.dns config field which specifies the token used implicitly during dns checks. [GH-17936]bind-var flag to consul acl binding-rule for templated policy variables. [GH-18719]consul acl templated-policy commands to read, list and preview templated policies. [GH-18816]IMPROVEMENTS:
CheckRegisterOpts to Agent API [GH-18943]Token field to ServiceRegisterOpts type in Agent API [GH-18983]-templated-policy, -templated-policy-file, -replace-templated-policy, -append-templated-policy, -replace-templated-policy-file, -append-templated-policy-file and -var flags for creating or updating tokens/roles. [GH-18708]tls.defaults.verify_server_hostname configuration option. This specifies the default value for any interfaces that support the verify_server_hostname option. [GH-17155]BUG FIXES:
/v1/catalog/services endpoint [GH-18322]performance.grpc_keepalive_timeout and performance.grpc_keepalive_interval now exist to allow for configuration on how often these dead connections will be cleaned up. [GH-19339]api: RaftLeaderTransfer now requires an id string. An empty string can be specified to keep the old behavior. [GH-17107]
BREAKING CHANGES:
FEATURE PREVIEW: Catalog v2
This release provides the ability to preview Consul's v2 Catalog and Resource API if enabled. The new model supports multi-port application deployments with only a single Envoy proxy. Note that the v1 and v2 catalogs are not cross compatible, and not all Consul features are available within this v2 feature preview. See the v2 Catalog and Resource API documentation for more information. The v2 Catalog and Resources API should be considered a feature preview within this release and should not be used in production environments.
Limitations
Known Issues
Significant Pull Requests
FEATURES:
acl.tokens.dns config field which specifies the token used implicitly during dns checks. [GH-17936]bind-var flag to consul acl binding-rule for templated policy variables. [GH-18719]consul acl templated-policy commands to read, list and preview templated policies. [GH-18816]IMPROVEMENTS:
CheckRegisterOpts to Agent API [GH-18943]Token field to ServiceRegisterOpts type in Agent API [GH-18983]-templated-policy, -templated-policy-file, -replace-templated-policy, -append-templated-policy, -replace-templated-policy-file, -append-templated-policy-file and -var flags for creating or updating tokens/roles. [GH-18708]tls.defaults.verify_server_hostname configuration option. This specifies the default value for any interfaces that support the verify_server_hostname option. [GH-17155]BUG FIXES:
Update google.golang.org/protobuf to v1.33.0 to address CVE-2024-24786. [GH-20801]
SECURITY:
google.golang.org/protobuf to v1.33.0 to address CVE-2024-24786. [GH-20801]alpine3.19. This resolves CVEs
CVE-2023-52425
CVE-2023-52426 [GH-20812]1.21.8. This resolves CVEs
CVE-2024-24783 (crypto/x509).
CVE-2023-45290 (net/http).
CVE-2023-45289 (net/http, net/http/cookiejar).
CVE-2024-24785 (html/template).
CVE-2024-24784 (net/mail). [GH-20812]IMPROVEMENTS:
backup_destinations config file object.BUG FIXES:
mesh: Update Envoy version to 1.26.7 to address CVE-2024-23324, CVE-2024-23325, CVE-2024-23322, CVE-2024-23323, CVE-2024-23327, and CVE-2023-44487 [GH…
SECURITY:
IMPROVEMENTS:
Internal.ServiceDump when mesh gateway is not used. [GH-20168]Internal.ServiceDump watch from proxycfg [GH-20168]BUG FIXES:
http protocol fails with a protocol-mismatch error. [GH-20481]connect: Remove usage of deprecated Envoy field match_subject_alt_names in favor of match_typed_subject_alt_names. [GH-19954]
KNOWN ISSUES:
SECURITY:
ubi9-minimal:9.3 as the base image. [GH-20014]IMPROVEMENTS:
match_subject_alt_names in favor of match_typed_subject_alt_names. [GH-19954]envoy.config.router.v3.WeightedCluster.total_weight. [GH-20011]envoy.config.cluster.v3.Cluster.http_protocol_options [GH-20010]envoy.config.cluster.v3.Cluster.http2_protocol_options, envoy.config.bootstrap.v3.Admin.access_log_path [GH-19940]envoy.extensions.filters.http.lua.v3.Lua.inline_code [GH-20012]BUG FIXES:
Upgrade to use Go 1.20.12. This resolves CVEs CVE-2023-45283: (path/filepath) recognize \??\ as a Root Local Device path prefix (Windows) CVE-2023-452…
SECURITY:
github.com/golang-jwt/jwt/v4 to v4.5.0 to address PRISMA-2022-0270. [GH-19705]path/filepath) recognize ??\ as a Root Local Device path prefix (Windows)
CVE-2023-45284: recognize device names with trailing spaces and superscripts (Windows)
CVE-2023-39326: (net/http) limit chunked data overhead
CVE-2023-45285: (cmd/go) go get may unexpectedly fallback to insecure git [GH-19840]IMPROVEMENTS:
stats_flush_interval to 60 seconds when using the Consul Telemetry Collector, unless custom stats sink are present or an explicit flush interval is configured. [GH-19663]BUG FIXES:
xds_fetch_timeout_ms option to proxy registrations that allows users to prevent endpoints from dropping when they have proxies with a large number of upstreams. [GH-19871]Update golang.org/x/net to v0.17.0 to address CVE-2023-39325 / CVE-2023-44487(x/net/http2). [GH-19225]
SECURITY:
golang.org/x/net to v0.17.0 to address CVE-2023-39325
/ CVE-2023-44487(x/net/http2). [GH-19225]net/http). [GH-19225]google.golang.org/grpc to 1.56.3.
This resolves vulnerability CVE-2023-44487. [GH-19414]BUG FIXES:
/v1/catalog/services endpoint [GH-18322]performance.grpc_keepalive_timeout and performance.grpc_keepalive_interval now exist to allow for configuration on how often these dead connections will be cleaned up. [GH-19339]Upgrade to use Go 1.20.8. This resolves CVEs CVE-2023-39320 (cmd/go), CVE-2023-39318 (html/template), CVE-2023-39319 (html/template), CVE-2023-39321 (…
SECURITY:
cmd/go),
CVE-2023-39318 (html/template),
CVE-2023-39319 (html/template),
CVE-2023-39321 (crypto/tls), and
CVE-2023-39322 (crypto/tls) [GH-18742]IMPROVEMENTS:
tcp_use_tls boolean. By default the agent will use the
TLS configuration in the tls.default stanza. [GH-18381]BUG FIXES:
/v1/agent/self not returning latest configuration [GH-18681]Update golang.org/x/net to v0.13.0 to address CVE-2023-3978. [GH-18358]
KNOWN ISSUES:
SECURITY:
golang.org/x/net to v0.13.0 to address CVE-2023-3978. [GH-18358]net/http) for uses of the standard library.
A separate change updates dependencies on golang.org/x/net to use 0.12.0. [GH-18190]crypto/tls). [GH-18358]FEATURES:
consul members command uses -filter expression to filter members based on bexpr. [GH-18223]consul operator raft list-peers command shows the number of commits each follower is trailing the leader by to aid in troubleshooting. [GH-17582]consul watch command uses -filter expression to filter response from checks, services, nodes, and service. [GH-17780]IMPROVEMENTS:
property-override builtin Envoy extension [GH-17759]operator/usage endpoint now returns node count
cli: consul operator usage command now returns node count [GH-17939]BUG FIXES:
consul connect envoy command when starting an API Gateway.
This health check would always fail. [GH-18011]PUT /acl/token/:AccessorID (update token), no longer requires AccessorID in the request body. Web UI can now update tokens. [GH-17739]jwt-provider config entries are created in the default namespace. [GH-18325]peering: Removed deprecated backward-compatibility behavior. Upstream overrides in service-defaults will now only apply to peer upstreams when the pee…
KNOWN ISSUES:
BREAKING CHANGES:
/v1/health/connect/ and /v1/health/ingress/ endpoints now immediately return 403 "Permission Denied" errors whenever a token with insufficient service:read permissions is provided. Prior to this change, the endpoints returned a success code with an empty result list when a token with insufficient permissions was provided. [GH-17424]peer field is provided.
Visit the 1.16.x upgrade instructions for more information. [GH-16957]SECURITY:
alpine:3.18. [GH-17719]v1/operator/audit-hash endpoint to ACL token with operator:read privileges.FEATURES:
POST /v1/operator/audit-hash endpoint to calculate the hash of the data used by the audit log hash function and salt.consul operator audit hash command to retrieve and compare the hash of the data used by the audit log hash function and salt.consul services export - for exporting a service to a peer or partition [GH-15654]AllowEnablingPermissiveMutualTLS setting to the mesh config entry and the MutualTLSMode setting to proxy-defaults and service-defaults. [GH-17035]property-override built-in Envoy extension that directly patches Envoy resources. [GH-17487]IMPROVEMENTS:
-filter option to consul config list for filtering config entries. [GH-17183]datacenter, ap (enterprise-only), and namespace (enterprise-only). Both short-hand and long-hand forms of these query params are now supported via the HTTP API (dc/datacenter, ap/partition, ns/namespace). [GH-17525]BUG FIXES:
peering: Removed deprecated backward-compatibility behavior. Upstream overrides in service-defaults will now only apply to peer upstreams when the pee…
BREAKING CHANGES:
/v1/health/connect/ and /v1/health/ingress/ endpoints now immediately return 403 "Permission Denied" errors whenever a token with insufficient service:read permissions is provided. Prior to this change, the endpoints returned a success code with an empty result list when a token with insufficient permissions was provided. [GH-17424]peer field is provided.
Visit the 1.16.x upgrade instructions for more information. [GH-16957]SECURITY:
v1/operator/audit-hash endpoint to ACL token with operator:read privileges.FEATURES:
POST /v1/operator/audit-hash endpoint to calculate the hash of the data used by the audit log hash function and salt.consul operator audit hash command to retrieve and compare the hash of the data used by the audit log hash function and salt.consul services export - for exporting a service to a peer or partition [GH-15654]AllowEnablingPermissiveMutualTLS setting to the mesh config entry and the MutualTLSMode setting to proxy-defaults and service-defaults. [GH-17035]property-override built-in Envoy extension that directly patches Envoy resources. [GH-17487]IMPROVEMENTS:
-filter option to consul config list for filtering config entries. [GH-17183]datacenter, ap (enterprise-only), and namespace (enterprise-only). Both short-hand and long-hand forms of these query params are now supported via the HTTP API (dc/datacenter, ap/partition, ns/namespace). [GH-17525]BUG FIXES:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Update google.golang.org/protobuf to v1.33.0 to address CVE-2024-24786. [GH-20801]
Enterprise LTS: Consul Enterprise 1.15 is a Long-Term Support (LTS) release.
SECURITY:
google.golang.org/protobuf to v1.33.0 to address CVE-2024-24786. [GH-20801]IMPROVEMENTS:
BUG FIXES:
mesh: Update Envoy versions to 1.28.1, 1.27.3, and 1.26.7 to address CVE-2024-23324, CVE-2024-23325, CVE-2024-23322, CVE-2024-23323, CVE-2024-23327, a…
SECURITY:
IMPROVEMENTS:
Internal.ServiceDump when mesh gateway is not used. [GH-20168]Internal.ServiceDump watch from proxycfg [GH-20168]BUG FIXES:
http protocol fails with a protocol-mismatch error. [GH-20481]Update RSA key generation to use a key size of at least 2048 bits. [GH-20112]
SECURITY:
ubi9-minimal:9.3 as the base image. [GH-20014]IMPROVEMENTS:
BUG FIXES:
Upgrade to use Go 1.20.12. This resolves CVEs CVE-2023-45283: (path/filepath) recognize \??\ as a Root Local Device path prefix (Windows) CVE-2023-452…
SECURITY:
github.com/golang-jwt/jwt/v4 to v4.5.0 to address PRISMA-2022-0270. [GH-19705]path/filepath) recognize ??\ as a Root Local Device path prefix (Windows)
CVE-2023-45284: recognize device names with trailing spaces and superscripts (Windows)
CVE-2023-39326: (net/http) limit chunked data overhead
CVE-2023-45285: (cmd/go) go get may unexpectedly fallback to insecure git [GH-19840]IMPROVEMENTS:
stats_flush_interval to 60 seconds when using the Consul Telemetry Collector, unless custom stats sink are present or an explicit flush interval is configured. [GH-19663]BUG FIXES:
xds_fetch_timeout_ms option to proxy registrations that allows users to prevent endpoints from dropping when they have proxies with a large number of upstreams. [GH-19871]Update golang.org/x/net to v0.17.0 to address CVE-2023-39325 / CVE-2023-44487(x/net/http2). [GH-19225]
SECURITY:
golang.org/x/net to v0.17.0 to address CVE-2023-39325
/ CVE-2023-44487(x/net/http2). [GH-19225]net/http). [GH-19225]google.golang.org/grpc to 1.56.3.
This resolves vulnerability CVE-2023-44487. [GH-19414]BUG FIXES:
/v1/catalog/services endpoint [GH-18322]performance.grpc_keepalive_timeout and performance.grpc_keepalive_interval now exist to allow for configuration on how often these dead connections will be cleaned up. [GH-19339]Upgrade to use Go 1.20.8. This resolves CVEs CVE-2023-39320 (cmd/go), CVE-2023-39318 (html/template), CVE-2023-39319 (html/template), CVE-2023-39321 (…
SECURITY:
cmd/go),
CVE-2023-39318 (html/template),
CVE-2023-39319 (html/template),
CVE-2023-39321 (crypto/tls), and
CVE-2023-39322 (crypto/tls) [GH-18742]IMPROVEMENTS:
BUG FIXES:
/v1/agent/self not returning latest configuration [GH-18681]Update golang.org/x/net to v0.13.0 to address CVE-2023-3978. [GH-18358]
SECURITY:
golang.org/x/net to v0.13.0 to address CVE-2023-3978. [GH-18358]net/http) for uses of the standard library.
A separate change updates dependencies on golang.org/x/net to use 0.12.0. [GH-18190]crypto/tls). [GH-18358]FEATURES:
consul members command uses -filter expression to filter members based on bexpr. [GH-18223]consul watch command uses -filter expression to filter response from checks, services, nodes, and service. [GH-17780]IMPROVEMENTS:
BUG FIXES:
consul connect envoy command when starting an API Gateway.
This health check would always fail. [GH-18011]Your coding agent can read these notes before it upgrades. Set up the MCP server →