Server-side Request Forgery (SSRF) Affecting github.com/hashicorp/vault package, versions >=1.14.0 <2.0.0-rc1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMHASHICORPVAULT-16110818
  • published20 Apr 2026
  • disclosed17 Apr 2026
  • creditUnknown

Introduced: 17 Apr 2026

CVE-2026-5052  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade github.com/hashicorp/vault to version 2.0.0-rc1 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through the ValidateHTTP01Challenge and ValidateTLSALPN01Challenge validation paths in builtin/logical/pki/acme_challenges.go. An attacker can make the ACME validator connect to loopback, link-local, unspecified, multicast, or other non-global-unicast targets by supplying a challenge domain that resolves to those addresses or by using a literal IP address. This lets an attacker drive Vault to probe internal or local services during challenge verification, exposing those services to unauthorized access attempts and causing ACME validation to fail for legitimate users.

CVSS Base Scores

version 4.0
version 3.1