Server-Side Request Forgery Vulnerability in Dogtag PKI ACME Responder
CVE-2026-18369

5.8MEDIUM

What is CVE-2026-18369?

A vulnerability exists in the ACME responder of Dogtag PKI where the HTTP-01 challenge validator improperly accepts IP address literals as DNS identifiers. This flaw allows an unauthenticated ACME account holder to exploit the system by following HTTP redirects, potentially leading to server-side request forgery (SSRF). This means that the Dogtag server can be tricked into sending HTTP GET requests to internal network services without proper validation of the targets, which could expose sensitive information. When using the InMemory database backend, responses from these internal services may be disclosed to the attacker via the errors generated during the ACME challenge.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.