Red Hat Certificate System
8 known vulnerabilities in Red Hat Certificate System, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-104988 CVSS 8.1 high A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is…
- CVE-2026-80110 CVSS 8.1 high A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using…
- CVE-2026-89059 CVSS 7.5 high A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the…
- CVE-2026-89058 CVSS 7.4 high A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in…
- CVE-2026-76561 CVSS 7.2 high A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does…
- CVE-2026-53682 CVSS 5.3 medium An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured…
- CVE-2026-11873 CVSS 6.5 medium An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for…
- CVE-2026-54513 CVSS 8.1 high jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until…