CVE Explorer
CVE-2026-25518
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. In versions from 1.18.0 to before 1.18.5 and from 1.19.0 to before 1.19.3, the cert-manager-controller performs DNS lookups during ACME DNS-01 processing (for zone discovery and propagation self-checks). By default, these lookups use standard unencrypted DNS. An attacker who can intercept and modify DNS traffic from the c
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-129","description":"CWE-129: Improper Validation of Array Index","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-704","description":"CWE-704: Incorrect Type Conversion or Cast","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"cert-manager","vendor":"cert-manager","versions":[{"status":"affected","version":">= 1.18.0, < 1.18.5"},{"status":"affected","version":">= 1.19.0, < 1.19.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-129","description":"CWE-129: Improper Validation of Array Index","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-704","description":"CWE-704: Incorrect Type Conversion or Cast","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/problemTypes/1/descriptions/0
Source references
7 source assertions{"name":"https://github.com/cert-manager/cert-manager/commit/409fc24e539711a07aae45ed45abbe03dfdad2cc","tags":["x_refsource_MISC"],"url":"https://github.com/cert-manager/cert-manager/commit/409fc24e539711a07aae45ed45abbe03dfdad2cc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/references/4
{"name":"https://github.com/cert-manager/cert-manager/commit/9a73a0b3853035827edd37ac463e4803ba10327d","tags":["x_refsource_MISC"],"url":"https://github.com/cert-manager/cert-manager/commit/9a73a0b3853035827edd37ac463e4803ba10327d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/references/5
{"name":"https://github.com/cert-manager/cert-manager/commit/d4faed26ae12115cceb807cdc12507ebc28980e2","tags":["x_refsource_MISC"],"url":"https://github.com/cert-manager/cert-manager/commit/d4faed26ae12115cceb807cdc12507ebc28980e2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/references/6
{"name":"https://github.com/cert-manager/cert-manager/pull/8467","tags":["x_refsource_MISC"],"url":"https://github.com/cert-manager/cert-manager/pull/8467"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/references/1
{"name":"https://github.com/cert-manager/cert-manager/pull/8468","tags":["x_refsource_MISC"],"url":"https://github.com/cert-manager/cert-manager/pull/8468"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/references/2
{"name":"https://github.com/cert-manager/cert-manager/pull/8469","tags":["x_refsource_MISC"],"url":"https://github.com/cert-manager/cert-manager/pull/8469"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/references/3
{"name":"https://github.com/cert-manager/cert-manager/security/advisories/GHSA-gx3x-vq4p-mhhv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/cert-manager/cert-manager/security/advisories/GHSA-gx3x-vq4p-mhhv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5621f43c35ddbc2629fc25dda686c539d3a07b5fa0fec51bc6410ae543599cf6 · sha256:692e4c227c287994… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.