Vault CE 2.0.0; Vault Enterprise 2.0.0, 1.21.5, 1.20.10, 1.19.16
Recorded credit
independently identified and reported by Oleh Konko of 1seal (HCSEC-2026-06)
Note
GHSA-8r5m-3f66-qpr3 / HCSEC-2026-06; Vault ACME validation did not reject local targets for http-01 and tls-alpn-01 challenges. v2.0.0 adds isValidChallengeIP and dialACMEValidationTarget, plus challenge_permitted_ip_ranges and challenge_excluded_ip_ranges configuration.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE registry state
PUBLISHED
CVE state checked
F-VAULT-ACME-SSRF-001: Outbound request trust. ACME validation dials attacker-controlled DNS destinations. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
pki/acme: reject unsafe validation targets during challenge verification
enterprise merged
details
Finding IDs
F-VAULT-ACME-SSRF-001
Status
enterprise merged
Reported date
Rationale
hardens ACME validation so HTTP-01 and TLS-ALPN-01 challenge dials reject loopback, link-local, unspecified, multicast, and similar unsafe targets before outbound connections. public PR #31828 was opened from the reporter branch, approved by the Vault maintainer, and copied into vault-enterprise #12959, which merged on 2026-03-12.
PR opened by
@1seal
PR state observed
closed; GitHub merged: false; 2026-09-24
PR observation basis
Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
Contribution boundary
@1seal opened this PR; this alone does not establish sole code authorship.
F-VAULT-ACME-SSRF-001: Outbound request trust. ACME validation dials attacker-controlled DNS destinations. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.