PT-2026-66452 · Red Hat+2 · Red Hat Certificate System 10+8
CVE-2026-18369
·
Published
2026-07-30
·
Updated
2026-07-30
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dogtag PKI (affected versions not specified)
Description
A flaw in the ACME responder allows the HTTP-01 challenge validator to accept IP address literals as DNS identifiers and follow HTTP redirects without verifying if the target is a public address. An unauthenticated ACME account holder can use this to perform Server-Side Request Forgery (SSRF), which is a technique that forces a server to make requests to an unintended location, causing the Dogtag server to send HTTP GET requests to internal network services. When using the InMemory database backend, the response body of these internal targets is disclosed to the attacker via the ACME challenge error.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Certificate System 10
Red Hat Certificate System 11
Red Hat Certificate System 9
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Dogtag Pki