{"id":"GHSA-gx3x-vq4p-mhhv","summary":"cert-manager-controller DoS via Specially Crafted DNS Response","details":"### Impact\n\nThe cert-manager-controller performs DNS lookups during ACME DNS-01 processing (for zone discovery and propagation self-checks). By default, these lookups use standard unencrypted DNS.\n\nAn attacker who can intercept and modify DNS traffic from the cert-manager-controller pod can insert a crafted entry into cert-manager's DNS cache. Accessing this entry will trigger a panic, resulting in Denial of Service (DoS) of the cert-manager controller.\n\nThe issue can also be exploited if the authoritative DNS server for the domain being validated is controlled by a malicious actor.\n\n### Patches\n\nThe vulnerability was introduced in cert-manager v1.18.0 and has been patched in cert-manager v1.19.3 and v1.18.5, which are the supported minor releases at the time of publishing.\n\ncert-manager versions prior to v1.18.0 are unaffected.\n\n### Workarounds\n\n- Using DNS-over-HTTPS reduces the risk of DNS traffic being intercepted and modified.\n    - Note that DNS-over-HTTPS does *not* prevent the risk of an attacker-controlled authoritative DNS server.\n\n### Resources\n\n- Fix for cert-manager 1.18: https://github.com/cert-manager/cert-manager/pull/8467\n- Fix for cert-manager 1.19: https://github.com/cert-manager/cert-manager/pull/8468\n- Fix for master branch: https://github.com/cert-manager/cert-manager/pull/8469\n\n### Credits\n\nHuge thanks to Oleh Konko (@1seal) for reporting the issue, providing a detailed PoC and an initial patch!","aliases":["BIT-cert-manager-2026-25518","CVE-2026-25518","GO-2026-4399"],"modified":"2026-09-10T03:50:35.167059566Z","published":"2026-02-02T22:11:06Z","database_specific":{"nvd_published_at":"2026-02-04T22:15:58Z","cwe_ids":["CWE-129","CWE-704"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-02T22:11:06Z"},"references":[{"type":"WEB","url":"https://github.com/cert-manager/cert-manager/security/advisories/GHSA-gx3x-vq4p-mhhv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25518"},{"type":"WEB","url":"https://github.com/cert-manager/cert-manager/pull/8467"},{"type":"WEB","url":"https://github.com/cert-manager/cert-manager/pull/8468"},{"type":"WEB","url":"https://github.com/cert-manager/cert-manager/pull/8469"},{"type":"WEB","url":"https://github.com/cert-manager/cert-manager/commit/409fc24e539711a07aae45ed45abbe03dfdad2cc"},{"type":"WEB","url":"https://github.com/cert-manager/cert-manager/commit/9a73a0b3853035827edd37ac463e4803ba10327d"},{"type":"WEB","url":"https://github.com/cert-manager/cert-manager/commit/d4faed26ae12115cceb807cdc12507ebc28980e2"},{"type":"PACKAGE","url":"https://github.com/cert-manager/cert-manager"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2026-4399"}],"affected":[{"package":{"name":"github.com/cert-manager/cert-manager","ecosystem":"Go","purl":"pkg:golang/github.com/cert-manager/cert-manager"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.18.0"},{"fixed":"1.18.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-gx3x-vq4p-mhhv/GHSA-gx3x-vq4p-mhhv.json"}},{"package":{"name":"github.com/cert-manager/cert-manager","ecosystem":"Go","purl":"pkg:golang/github.com/cert-manager/cert-manager"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.19.0"},{"fixed":"1.19.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-gx3x-vq4p-mhhv/GHSA-gx3x-vq4p-mhhv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}