PT-2026-66452 · Red Hat+2 · Red Hat Certificate System 10+8

CVE-2026-18369

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dogtag PKI (affected versions not specified)
Description A flaw in the ACME responder allows the HTTP-01 challenge validator to accept IP address literals as DNS identifiers and follow HTTP redirects without verifying if the target is a public address. An unauthenticated ACME account holder can use this to perform Server-Side Request Forgery (SSRF), which is a technique that forces a server to make requests to an unintended location, causing the Dogtag server to send HTTP GET requests to internal network services. When using the InMemory database backend, the response body of these internal targets is disclosed to the attacker via the ACME challenge error.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18369

Affected Products

Red Hat Certificate System 10
Red Hat Certificate System 11
Red Hat Certificate System 9
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Dogtag Pki