CVE 5.3 MEDIUM

Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS_CVE-2026-5052

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Basic Information

ID CVE-2026-5052
Source HashiCorp
Published Apr 17, 2026 at 02:55

Affected Product

Vendor HashiCorp
Product Vault
Version 1.15.0
Affected Versions HashiCorp Vault 1.15.0
HashiCorp Vault Enterprise 1.15.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.