What is CVE-2026-18369?
A vulnerability in Dogtag PKI's ACME responder allows the HTTP-01 challenge validator to accept IP addresses as DNS identifiers and follow HTTP redirects without verifying the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF). Affected Dogtag PKI deployments should be updated immediately to mitigate the risk.
Azərbaycanca: CVE-2026-18369: Dogtag PKI-nin ACME cavabverənində aşkar edilmiş boşluq HTTP-01 sorğu doğrulayıcısının DNS identifikatorları kimi IP ünvanlarını qəbul etməsinə və HTTP yönləndirmələrini hədəfin ictimai ünvan olduğunu yoxlamadan izləməsinə imkan verir. Bu, autentifikasiya olunmamış ACME hesab sahibinə server tərəfli sorğu saxtakarlığı (SSRF) həyata keçirməyə şərait yaradır. Təsirə məruz qalan sistemlərdə dərhal müvafiq Dogtag PKI yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which Dogtag PKI component is affected by CVE-2026-18369?
CVE-2026-18369 affects the ACME responder component of Dogtag PKI, specifically the HTTP-01 challenge validator.
What can an attacker do by exploiting this vulnerability?
An unauthenticated ACME account holder can exploit this vulnerability to perform server-side request forgery (SSRF).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.