VulnSea

dogtag-pki vulnerabilities

CVEs whose affected-version data names the dogtag-pki package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-80110High· 8.1
yesterday

A flaw was found in pki-core

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to ove…

TwilightRed Hat · pki-corevia NVD
CVE-2026-89059High· 7.5PoC
4d ago

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafte…

MidnightRed Hat · RESTEasyEPSS 0.56%via NVD
CVE-2026-89058High· 7.4PoC
4d ago

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. Thi…

MidnightRed Hat · RESTEasyEPSS 0.42%via NVD
CVE-2026-76561High· 7.2
2w ago

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Admi…

TwilightRed Hat · pki-coreEPSS 0.59%via NVD
CVE-2026-18369Medium· 5.8
1mo ago

Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated AC…

SunlitRed Hat · redhat-pki:10EPSS 0.22%via CVEORG
dogtag-pki vulnerabilities (CVEs) · VulnSea