vaultGHSA-8r5m-3f66-qpr3
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
Medium5.3CVE-2026-5052 · Published Apr 17, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.14.0, <= 1.21.4 | No fix yet |
Details and references
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- BIT-vault-2026-5052, CVE-2026-5052, GO-2026-5262
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 17 | HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization CVE-2026-4525High7.5no fix yet | High7.5 | No fix yet |
| Apr 17 | HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service CVE-2026-3605High8.1no fix yet | High8.1 | No fix yet |
| Apr 17 | HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations CVE-2026-5807High7.5no fix yet | High7.5 | No fix yet |
| Oct 232025 | Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON CVE-2025-12044High7.5fixed in 1.21.0 | High7.5 | 1.21.0 |
| Oct 232025 | HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass CVE-2025-11621High8.1fixed in 1.21.0 | High8.1 | 1.21.0 |
| Aug 282025 | HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads CVE-2025-6203High7.5fixed in 1.20.3 | High7.5 | 1.20.3 |