Server-Side Request Forgery (SSRF) in kdcproxy - CVE-2025-59088
Published: November 19, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. A remote attacker can probe internal network topology and firewall rules, perform port scanning, and exfiltrate data.
Affected software
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python-kdcproxy
python-kdcproxy (Red Hat package)
python3-kdcproxy
python3-jwcrypto
custodia
python3-custodia
ipa-healthcheck
ipa-healthcheck-core
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm-devel
softhsm
ipa-server-dns
ipa-client-common
ipa-python-compat
ipa-client
ipa-client-epn
ipa-client-samba
ipa-server
ipa-selinux
ipa-server-trust-ad
ipa-common
python3-ipatests
python3-ipaserver
python3-ipalib
python3-ipaclient
ipa-server-common
python3-qrcode
python3-qrcode-core
bind-dyndb-ldap
How to mitigate CVE-2025-59088
python-kdcproxy - update to 0.3.2-3
python-kdcproxy (Red Hat package) - addressed in versions 0.3.2-3.el7_9.3, 1.0.0-7.el9_0.1, 1.0.0-7.el9_2.1, 1.0.0-7.el9_4.1, 1.0.0-19.el10_1
python3-kdcproxy - addressed in versions 0.4-5, 1.0.0-4
python3-jwcrypto - update to 0.5.0-2
custodia - update to 0.6.0-3
python3-custodia - update to 0.6.0-3
ipa-healthcheck - update to 0.12-6
ipa-healthcheck-core - update to 0.12-6
slapi-nis - update to 0.60.0-4.0.1
python-kdcproxy - update to 1.0.0-2
python3-kdcproxy - update to 1.0.0-2
python3-pyusb - update to 1.0.0-9.1
python-kdcproxy - addressed in versions 1.1.0-1.fc41, 1.1.0-1.fc42, 1.1.0-1.fc43, 1.1.0-1.fc44
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-2
softhsm-devel - update to 2.6.0-5
softhsm - update to 2.6.0-5
ipa-server-dns - update to 4.9.13-20.0.1
ipa-client-common - update to 4.9.13-20.0.1
ipa-python-compat - update to 4.9.13-20.0.1
ipa-client - update to 4.9.13-20.0.1
ipa-client-epn - update to 4.9.13-20.0.1
ipa-client-samba - update to 4.9.13-20.0.1
ipa-server - update to 4.9.13-20.0.1
ipa-selinux - update to 4.9.13-20.0.1
ipa-server-trust-ad - update to 4.9.13-20.0.1
ipa-common - update to 4.9.13-20.0.1
python3-ipatests - update to 4.9.13-20.0.1
python3-ipaserver - update to 4.9.13-20.0.1
python3-ipalib - update to 4.9.13-20.0.1
python3-ipaclient - update to 4.9.13-20.0.1
ipa-server-common - update to 4.9.13-20.0.1
python3-qrcode - update to 5.3-1
python3-qrcode-core - update to 5.3-1
bind-dyndb-ldap - update to 11.6-6
External References
Related Security Bulletins
- Multiple vulnerabilities in kdcproxy
- Fedora 41 update for python-kdcproxy
- Fedora 42 update for python-kdcproxy
- Fedora 43 update for python-kdcproxy
- Red Hat Enterprise Linux 10 update for python-kdcproxy
- Red Hat Enterprise Linux 9 update for python-kdcproxy
- Red Hat Enterprise Linux 9 update for python-kdcproxy
- Anolis OS update for idm:DL1 module
- Red Hat Enterprise Linux 9 update for python-kdcproxy
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- openEuler update for python-kdcproxy
- Anolis OS update for python-kdcproxy
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for python-kdcproxy
- Fedora 44 update for python-kdcproxy
- Anolis OS update for python-kdcproxy