Skip to content
Red HatCVE-2026-18369

Red Hat Dogtag PKI: server-side request forgery

Medium5.8CVE-2026-18369 · Published Jul 30, 2026 · updated Sep 14, 2026

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Certificate System 10
Product
all versionsNo fix yet
Red Hat Certificate System 11
Product
all versionsNo fix yet
Red Hat Certificate System 9
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
ansible-collection-redhat-leapp: information disclosure
Medium6.2Jul 30
ansible-collection-redhat-leapp.: insecure permissions
Medium5.5Jul 30
Red Hat Samba: out-of-bounds read
Medium5.3Jul 30
Red Hat Enterprise Linux 10: improper authorization
High8.8Jul 30
Red Hat Samba: denial of service
Medium5.3Jul 30
Red Hat Cost Management Metrics Operator: server-side request forgery
High7.6Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.