Research / Finding
cert-manager-controller DoS via Specially Crafted DNS Response F-CERTMGR-DNS-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
5.9medium
cert-manager-controller DoS via Specially Crafted DNS Response
Fixed in: cert-manager v1.18.5, v1.19.3
patched
details
Finding IDs F-CERTMGR-DNS-001 CVE CVE-2026-25518 GHSA GHSA-gx3x-vq4p-mhhv Status patched Fixed in cert-manager v1.18.5, v1.19.3 CVSS vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVE registry state PUBLISHED CVE state checked 23 Sep 2026 Upstream title cert-manager-controller DoS via Specially Crafted DNS Response Upstream CWE CWE-129, CWE-704 Upstream publication 2 Feb 2026 Upstream updated 3 Feb 2026 Metadata fetched 23 Sep 2026 Upstream @1seal credit @1seal: reporter (accepted) F-CERTMGR-DNS-001: Input / state handling. Malformed DNS response fields reach a panic. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-CERTMGR-DNS-001
Security area (1seal assessment): Availability. Malformed DNS response fields reach a panic. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .