CVE-2026-11873

An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 12:17

Updated : 2026-09-01 21:03


NVD link : CVE-2026-11873

Mitre link : CVE-2026-11873

CVE.ORG link : CVE-2026-11873


JSON object : View

Products Affected

No product.

CWE
CWE-209

Generation of Error Message Containing Sensitive Information