BIT-vault-2026-5052

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/vault/BIT-vault-2026-5052.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-vault-2026-5052
Aliases
Published
2026-04-21T12:15:56Z
Modified
2026-09-08T08:48:21Z
Summary
Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
Details

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Database specific
{
    "cpes": [
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:*:go:*:*",
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:go:*:*",
        "cpe:2.3:a:hashicorp:vault:*:*:*:*:community:go:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / vault

Package

Name
vault
Purl
pkg:bitnami/vault

Severity

  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0.10.0
Fixed
2.0.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/vault/BIT-vault-2026-5052.json"