H

HashiCorp Consul

H
HashiCorp Consul Networking v2.1.0-rc1

v2.1.0-rc1

2.1.0-rc1 (September 28, 2026) BREAKING CHANGES: cli: Migrated the consul connect redirect-traffic command from iptables/ip6tables to nftables (nft). The command now uses the sdk/nftables package, which applies all IPv4 and IPv6 rules atomically in a single pass via the nftables inet address family, instead of separate iptables and ip6tables invocations. [GH-23785] cli: Transparent proxy exclusion…

H
HashiCorp Consul Networking v0.19.0-rc1

sdk/v0.19.0-rc1: Backport terminating gateway credential injection structs (#23939)

structs: backport inference gateway types to CE Adds the inference-gateway service kind, config entry kind, and their API, structs, agent-config, and proto surface so consumers such as consul-k8s can build against them. The inference gateway is an enterprise feature: CE rejects the config entry in Validate and the service kind in NodeService.Validate. Mirrors the CAMP structs backport (#23842). Th…

H
HashiCorp Consul Networking v2.0.4

v2.0.4

2.0.4 (September 10, 2026) BREAKING CHANGES: acl: Tokens that hold service:write but not mesh:write will now receive a permission-denied error when attempting to attach builtin/lua or builtin/wasm EnvoyExtensions (or upstream envoy_listener_json/envoy_cluster_json escape-hatch overrides) to a service-defaults config entry, or when registering a connect-proxy sidecar with bootstrap or xDS escape-ha…

H
HashiCorp Consul Networking v2.0.2

v2.0.2

2.0.2 (July 8, 2026) SECURITY: Upgrade alpine base image version to 3.24 to address [CVE-2026-41989], [ALPINE-CVE-2026-2100]. [GH-23711] dependency: Upgrade Serf and Memberlist to use the latest versions. [GH-23704] xds: Return errors when injecting the L4 intention (RBAC) filter or the mTLS transport socket onto an inbound public listener, so the listener is not served without intention enforceme…

H
HashiCorp Consul Networking v2.0.3

v2.0.3

2.0.3 (August 7, 2026) SECURITY: Update brace-expansion to address GHSA-rgw5-rvv9-x895 (DoS via unbounded intermediate arrays). [GH-23786] Update fast-uri to address GHSA-7p8r-x3mc-p8w7 (Host Confusion via backslash authority introducer). [GH-23786] Update golang.org/x/text to v0.39.0 to address GO-2026-5970. [GH-23761] Update google.golang.org/grpc to v1.82.1 to address GHSA-hrxh-6v49-42gf. [GH-2…

H
HashiCorp Consul Networking v2.0.1

v2.0.1

2.0.1 (June 18, 2026) SECURITY: Upgrade go version to 1.26.4 to address GO-2026-5039, GO-2026-5038,GO-2026-5037 [GH-23637] connect: Upgrade envoy version to 1.37.4, 1.36.8, 1.35.12; Add new version of Envoy 1.38.2 and remove 1.34.14 [GH-23664] IMPROVEMENTS: dockerfile: layer reduction by merging RUN commands and minor changes following best practices. [GH-23650] product-telemetry: product usage re…

H
HashiCorp Consul Networking v2.0.0

v2.0.0

2.0.0 (May 22, 2026) SECURITY: connect: Upgrade envoy version to 1.37.2 and newer versions [GH-23469] go: Upgrade go version to 1.26 [GH-23493] agent: Increased default HTTP server timeouts to prevent breaking long-polling blocking queries. read_timeout and write_timeout are now set to 15 minutes (up from 30 seconds), while read_header_timeout (10s) and idle_timeout (120s) still provide protection…

H
HashiCorp Consul Networking v2.0.0-rc2

v2.0.0-rc2

2.0.0-rc2 (May 15, 2026) SECURITY: agent: Increased default HTTP server timeouts to prevent breaking long-polling blocking queries. read_timeout and write_timeout are now set to 15 minutes (up from 30 seconds), while read_header_timeout (10s) and idle_timeout (120s) still provide protection against Slowloris attacks. All timeouts remain configurable via the http_config block. [GH-23267] api-gatewa…