Search CVE reports


Toggle filters

1 – 10 of 22 results


CVE-2026-76561

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-53682

Medium priority
Needs evaluation

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-18369

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address....

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-18047

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-17039

Medium priority
Needs evaluation

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-4727

Medium priority
Needs evaluation

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-2414

Medium priority

Some fixes available 1 of 4

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Fixed Ignored Ignored
Show less packages

CVE-2022-2393

Medium priority
Needs evaluation

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-3551

Low priority
Needs evaluation

A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-25715

Medium priority

Some fixes available 1 of 8

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Not affected Vulnerable Vulnerable
Show less packages