boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-18369

Red Hat Red Hat Certificate System 10.4 EUS for RHEL-8 — Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  N  N    5.8   .0022   11.9     —
AFFECTED
  Product                                         Versions     Fixed
  Red Hat Certificate System 10.4 EUS for RHEL-8  unspecified  8060020260814202723.07fb4edf
  Red Hat Certificate System 10                   unspecified  —
  Red Hat Certificate System 11                   unspecified  —
  Red Hat Certificate System 9                    unspecified  —
  Red Hat Certificate System 9                    unspecified  —
  Red Hat Enterprise Linux 10                     unspecified  —
  Red Hat Enterprise Linux 6                      unspecified  —
  Red Hat Enterprise Linux 7                      unspecified  —
  Red Hat Enterprise Linux 8                      unspecified  —
  Red Hat Enterprise Linux 9                      unspecified  —
TIMELINE
  Jul 30  Reserved by redhat
  Jul 30  Published (CNA: redhat)
  Sep 13  PATCH SHIPPED — CVE-2026-18369 (Red Hat Certificate System 10.4 EUS for RHEL-8). Fixed in Red Hat Certificate System 10.4 EUS for RHEL-8 8060020260814202723.07fb4edf.
CWE-918 · CNA: redhat · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis

Description

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
July 30, 2026ReservedReserved by redhat
July 30, 2026PublishedPublished (CNA: redhat)
September 13, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-18369 (Red Hat Certificate System 10.4 EUS for RHEL-8). Fixed in Red Hat Certificate System 10.4 EUS for RHEL-8 8060020260814202723.07fb4edf.

Affected

Affected products and packages — 10 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat Certificate System 10.4 EUS for RHEL-8——8060020260814202723.07fb4edf
Red HatRed Hat Certificate System 10———
Red HatRed Hat Certificate System 11———
Red HatRed Hat Certificate System 9———
Red HatRed Hat Certificate System 9———
Red HatRed Hat Enterprise Linux 10———
Red HatRed Hat Enterprise Linux 6———
Red HatRed Hat Enterprise Linux 7———
Red HatRed Hat Enterprise Linux 8———
Red HatRed Hat Enterprise Linux 9———

Weaknesses

CWE-918

References (3)

Related

Authoritative record: CVE-2026-18369 at cve.org

Vendors: red hat

Weaknesses: CWE-918

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-18369 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.