CVE-2025-59088 Details
Description
If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. This creates a server-side request forgery vulnerability, since an attacker could send a request for a realm matching a DNS zone where they created SRV records pointing to arbitrary ports and hostnames (which may resolve to loopback or internal IP addresses). This vulnerability can be exploited to probe internal network topology and firewall rules, perform port scanning, and exfiltrate data. Deployments where the "use_dns" setting is explicitly set to false are not affected.
A server-side request forgery (SSRF) vulnerability has been identified in Python KDCProxy. This issue arises when KDCProxy receives a request for a realm without defined server addresses. By default, it queries SRV records in the DNS zone of the requested realm. An attacker can exploit this by sending requests that manipulate SRV records to point to arbitrary ports and hostnames, potentially leading to data exfiltration and probing of internal network defenses. The vulnerability affects several Red Hat Enterprise Linux versions, including 8, 9, 9.6 Extended Update Support, and 10.0 Extended Update Support.
Update to the latest version of Python KDCProxy. For Red Hat Enterprise Linux users, this update is available through the Red Hat Update System. Consult the Red Hat Enterprise Linux 8, 9, or 10 documentation for specific update instructions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 12, 2025CISA-ADP
Assessed Nov 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat Enterprise Linux | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux Server | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux for IBM z Systems | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux for Power | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux for ARM | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux Server for Power LE | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux for x86_64 | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux for ARM 64 | All versions |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 9, 2025 | CVE Modified | [email protected] |
| Nov 20, 2025 | CVE Modified | [email protected] |
| Nov 19, 2025 | CVE Modified | [email protected] |
| Nov 17, 2025 | CVE Modified | [email protected] |
| Nov 12, 2025 | CVE Modified | [email protected] |
| Nov 12, 2025 | New CVE Received | [email protected] |
Volerion