A AegiFlow
MEDIUMCVSS 5.3EPSS 0.3%

CVE-2026-5052

HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

Published
2026-04-17
Modified
2026-07-21
EPSS percentile
26%
Aliases
GHSA-8r5m-3f66-qpr3
Sources
github-advisory

Summary

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/hashicorp/vault

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.