Search CVE reports


Toggle filters

1 – 10 of 21 results


CVE-2026-53682

Medium priority
Needs evaluation

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-18369

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address....

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-18047

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-17039

Medium priority
Needs evaluation

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-4727

Medium priority
Needs evaluation

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-2414

Medium priority

Some fixes available 1 of 4

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Fixed Ignored Ignored
Show less packages

CVE-2022-2393

Medium priority
Needs evaluation

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-3551

Low priority
Needs evaluation

A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-25715

Medium priority

Some fixes available 1 of 8

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-1721

Low priority
Vulnerable

A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting...

1 affected package

dogtag-pki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dogtag-pki Not in release Not in release Needs evaluation Vulnerable Needs evaluation
Show less packages