Server-Side Request Forgery (SSRF) in Palo Alto PAN-OS - CVE-2026-0258
Published: May 19, 2026
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to server-side request forgery (SSRF) in the IKEv2 certificate URL fetching functionality when processing IKEv2 certificate URL fetching. A remote attacker can cause the firewall to send network requests to unintended destinations to cause a denial of service.
This issue is applicable only to configurations with a site-to-site VPN gateway with IKEv2 configured.