GHSA-gx3x-vq4p-mhhv
cert-manager-controller DoS via Specially Crafted DNS Response
Quick fix
GHSA-gx3x-vq4p-mhhv — github.com/cert-manager/cert-manager: upgrade to the fixed version with the command below.
go get github.com/cert-manager/cert-manager@v1.18.5Details
### Impact
The cert-manager-controller performs DNS lookups during ACME DNS-01 processing (for zone discovery and propagation self-checks). By default, these lookups use standard unencrypted DNS.
An attacker who can intercept and modify DNS traffic from the cert-manager-controller pod can insert a crafted entry into cert-manager's DNS cache. Accessing this entry will trigger a panic, resulting in Denial of Service (DoS) of the cert-manager controller.
The issue can also be exploited if the authoritative DNS server for the domain being validated is controlled by a malicious actor.
### Patches
The vulnerability was introduced in cert-manager v1.18.0 and has been patched in cert-manager v1.19.3 and v1.18.5, which are the supported minor releases at the time of publishing.
cert-manager versions prior to v1.18.0 are unaffected.
### Workarounds
- Using DNS-over-HTTPS reduces the risk of DNS traffic being intercepted and modified. - Note that DNS-over-HTTPS does *not* prevent the risk of an attacker-controlled authoritative DNS server.
### Resources
- Fix for cert-manager 1.18: https://github.com/cert-manager/cert-manager/pull/8467 - Fix for cert-manager 1.19: https://github.com/cert-manager/cert-manager/pull/8468 - Fix for master branch: https://github.com/cert-manager/cert-manager/pull/8469
### Credits
Huge thanks to Oleh Konko (@1seal) for reporting the issue, providing a detailed PoC and an initial patch!
Are you affected?
Enter the version of the package you're using.
Affected packages
1.18.0Fixed in: 1.18.5go get github.com/cert-manager/cert-manager@v1.18.51.19.0Fixed in: 1.19.3go get github.com/cert-manager/cert-manager@v1.19.3References
- https://github.com/cert-manager/cert-manager/security/advisories/GHSA-gx3x-vq4p-mhhv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-25518[ADVISORY]
- https://github.com/cert-manager/cert-manager/pull/8467[WEB]
- https://github.com/cert-manager/cert-manager/pull/8468[WEB]
- https://github.com/cert-manager/cert-manager/pull/8469[WEB]
- https://github.com/cert-manager/cert-manager/commit/409fc24e539711a07aae45ed45abbe03dfdad2cc[WEB]
- https://github.com/cert-manager/cert-manager/commit/9a73a0b3853035827edd37ac463e4803ba10327d[WEB]
- https://github.com/cert-manager/cert-manager/commit/d4faed26ae12115cceb807cdc12507ebc28980e2[WEB]
- https://github.com/cert-manager/cert-manager[PACKAGE]
- https://pkg.go.dev/vuln/GO-2026-4399[WEB]