If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. This creates a server-side request forgery vulnerability, since an attacker could send a request for a realm matching a DNS zone where they created SRV records pointing to arbitrary ports and hostnames (which may resolve to loopback or internal IP addresses). This vulnerability can be exploited to probe internal network topology and firewall rules, perform port scanning, and exfiltrate data. Deployments where the "use_dns" setting is explicitly set to false are not affected.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade custodiaUpgrade python3-ipaclientUpgrade bind-dyndb-ldapUpgrade ipa-client-commonUpgrade python3-pyusbUpgrade softhsm-develUpgrade ipa-commonUpgrade ipa-server-commonUpgrade ipa-clientUpgrade ipa-python-compatUpgrade ipa-client-sambaUpgrade python3-ipalibUpgrade python3-jwcryptoUpgrade python3-ipaserverUpgrade python3-qrcode-coreUpgrade softhsmUpgrade opendnssecUpgrade ipa-healthcheckUpgrade ipa-client-epnUpgrade python3-yubicoUpgrade slapi-nisUpgrade ipa-healthcheck-coreUpgrade python3-ipatestsUpgrade ipa-server-dnsUpgrade python3-custodiaUpgrade python3-qrcodeUpgrade ipa-serverUpgrade ipa-server-trust-adUpgrade python3-kdcproxyUpgrade ipa-selinux | Nov 20, 2025 | Nov 12, 2025 |
| Amazon Linux Ami 2 | — | Upgrade python-kdcproxy | May 20, 2026 | May 20, 2026 |
| Oracle_linux | — | Upgrade ipa-healthcheck-coreUpgrade python3-qrcode-coreUpgrade bind-dyndb-ldapUpgrade python3-pyusbUpgrade python3-kdcproxyUpgrade ipa-server-commonUpgrade python3-custodiaUpgrade softhsmUpgrade ipa-client-commonUpgrade ipa-server-dnsUpgrade python3-qrcodeUpgrade ipa-client-sambaUpgrade python3-ipaclientUpgrade ipa-client-epnUpgrade ipa-clientUpgrade python3-ipalibUpgrade python3-ipaserverUpgrade custodiaUpgrade softhsm-develUpgrade python-kdcproxyUpgrade opendnssecUpgrade ipa-serverUpgrade ipa-python-compatUpgrade ipa-server-trust-adUpgrade ipa-commonUpgrade ipa-selinuxUpgrade python3-jwcryptoUpgrade ipa-healthcheckUpgrade python3-ipatestsUpgrade slapi-nisUpgrade python3-yubico | Nov 17, 2025 | Nov 12, 2025 |
| Redhat_linux | — | Upgrade opendnssecUpgrade ipa-clientUpgrade ipa-client-sambaUpgrade ipa-client-epnUpgrade python3-qrcode-coreUpgrade softhsmUpgrade softhsm-develUpgrade ipa-healthcheck-coreUpgrade opendnssec-debuginfoUpgrade ipa-serverUpgrade ipa-python-compatUpgrade slapi-nis-debugsourceUpgrade python3-custodiaUpgrade python3-ipaserverUpgrade bind-dyndb-ldap-debuginfoUpgrade python3-qrcodeUpgrade python3-ipaclientUpgrade ipa-server-dnsUpgrade slapi-nisUpgrade ipa-debuginfoUpgrade python-kdcproxyUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-commonUpgrade ipa-client-debuginfoUpgrade python3-kdcproxyUpgrade ipa-server-commonUpgrade ipa-healthcheckUpgrade bind-dyndb-ldapUpgrade bind-dyndb-ldap-debugsourceUpgrade python3-ipatestsUpgrade python3-ipalibUpgrade ipa-selinuxUpgrade softhsm-debuginfoUpgrade ipa-client-commonUpgrade slapi-nis-debuginfoUpgrade custodiaUpgrade softhsm-debugsourceUpgrade python3-pyusbUpgrade opendnssec-debugsourceUpgrade ipa-server-debuginfoUpgrade ipa-debugsourceUpgrade python3-yubicoUpgrade ipa-server-trust-ad | Nov 14, 2025 | Nov 12, 2025 |
| Rocky_linux | — | Upgrade opendnssec-debugsourceUpgrade slapi-nisUpgrade ipa-server-debuginfoUpgrade ipa-server-trust-adUpgrade slapi-nis-debuginfoUpgrade slapi-nis-debugsourceUpgrade ipa-client-sambaUpgrade bind-dyndb-ldap-debuginfoUpgrade ipa-clientUpgrade softhsm-develUpgrade opendnssec-debuginfoUpgrade ipa-debuginfoUpgrade opendnssecUpgrade ipa-serverUpgrade softhsmUpgrade ipa-client-debuginfoUpgrade softhsm-debugsourceUpgrade bind-dyndb-ldapUpgrade softhsm-debuginfoUpgrade ipa-client-epnUpgrade ipa-debugsourceUpgrade ipa-server-trust-ad-debuginfoUpgrade bind-dyndb-ldap-debugsource | Feb 5, 2026 | Nov 21, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub