<Vulnerability name="CVE-2026-18369">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-30T10:02:44</PublicDate>
    <Bugzilla id="2509234" url="https://bugzilla.redhat.com/show_bug.cgi?id=2509234" xml:lang="en:us">
dogtag-pki: pki-core: redhat-pki: pki: ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-918</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.
    </Details>
    <Statement xml:lang="en:us">
Red Hat rates this Moderate because exploitation is limited to HTTP GET requests (no integrity impact), the attacker cannot read internal responses on production-supported backends (low confidentiality impact), and the ACME responder must be explicitly deployed. The Scope is Changed (S:C) because the ACME responder causes the Dogtag server to make outbound requests to services outside its own trust boundary, but the actual information gained on supported configurations is limited to network topology probing. While the SSRF is GET-only and does not directly allow data modification, administrators should be aware that internal services reachable from the Dogtag host which perform actions on HTTP GET (such as cloud instance metadata endpoints that issue temporary credentials) could be indirectly affected.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:certificate_system:10">
        <ProductName>Red Hat Certificate System 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>redhat-pki:10/redhat-pki</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:certificate_system:11">
        <ProductName>Red Hat Certificate System 11</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>redhat-pki</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:certificate_system:9">
        <ProductName>Red Hat Certificate System 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>pki-core</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:certificate_system:9">
        <ProductName>Red Hat Certificate System 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>redhat-pki</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>dogtag-pki</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>pki-core</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>pki-core</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>pki-core:10.6/pki-core</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>pki-core</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-18369
https://nvd.nist.gov/vuln/detail/CVE-2026-18369
    </References>
</Vulnerability>