---
id: CVE-2026-18369
title: >-
  Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip
  literal identifiers and unvalidated redirects
summary: >-
  A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge
  validator accepts IP address literals as dns identifiers and follows HTTP
  redirects without validating that the target is a public address. An
  unauthenticated AC…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-918
vendor: Red Hat
product: 'redhat-pki:10'
affected:
  - 'redhat-pki:10 (all versions)'
  - 'redhat-pki:10/redhat-pki (all versions)'
  - redhat-pki (all versions)
  - pki-core (all versions)
  - redhat-pki (all versions)
  - dogtag-pki (all versions)
  - pki-core (all versions)
  - pki-core (all versions)
  - 'pki-core:10.6/pki-core (all versions)'
  - pki-core (all versions)
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-07-30T13:43:45.999638Z'
published: '2026-07-30'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T05:28:08.089Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-18369'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:67110'
    label: 'RHSA-2026:67110'
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18369'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2509234'
    label: RHBZ#2509234
tags:
  - cve.org
epss: 0.00224
epssPercentile: 0.11655
ingestedAt: '2026-09-14T15:23:07.465Z'
---

## Overview

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.

## Affected

- `redhat-pki:10 (all versions)`
- `redhat-pki:10/redhat-pki (all versions)`
- `redhat-pki (all versions)`
- `pki-core (all versions)`
- `redhat-pki (all versions)`
- `dogtag-pki (all versions)`
- `pki-core (all versions)`
- `pki-core (all versions)`
- `pki-core:10.6/pki-core (all versions)`
- `pki-core (all versions)`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
