CVE-2026-11873CWE-209

CVE-2026-11873

Medium · published September 1, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
24.9
In the wild
Unconfirmed
What it is

An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00324 · 24.9th percentile
Weakness
CWE-209 · Generation of Error Message Containing Sensitive Information
Published
2026-09-01T16:17Z
References (2)
EPSS history
Timeline
  • 03 SEP 03:28Z
    EPSS moved — → 0%
    epss
  • 01 SEP 11:54Z
    Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosure
    cvelistv5