HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
Moderate severity
GitHub Reviewed
Published
Apr 17, 2026
to the GitHub Advisory Database
•
Updated Apr 18, 2026
Package
Affected versions
>= 1.14.0, <= 1.21.4
Patched versions
None
Description
Published by the National Vulnerability Database
Apr 17, 2026
Published to the GitHub Advisory Database
Apr 17, 2026
Reviewed
Apr 18, 2026
Last updated
Apr 18, 2026
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
References