CVE-2026-18369Medium· 5.8▾ SunlitA flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated AC…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.2%
0.2% → 0.2%
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.
redhat-pki:10 (all versions)redhat-pki:10/redhat-pki (all versions)redhat-pki (all versions)pki-core (all versions)redhat-pki (all versions)dogtag-pki (all versions)pki-core (all versions)pki-core (all versions)pki-core:10.6/pki-core (all versions)pki-core (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84721Medium· 6.4A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend
CVE-2026-12564Critical· 9.6A flaw was found in the AAP Controller's HashiCorp Vault credential plugin
CVE-2026-15378Critical· 9.3A flaw was found in the `guardrails-detectors` component
CVE-2026-15927Medium· 6.8A flaw was found in Red Hat Quay's repository-level mirror configuration feature
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-0532High· 8.6External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connect…