Junglewise Threat Intelligence

CVE-2025-59088: latchset kdcproxy SSRF via DNS SRV records

CVE-2025-59088 · Severity: high · CVSS 8.6 · Published 2025-11-12

Vendors: Red Hat.

Executive brief

kdcproxy is a service used to proxy Kerberos authentication traffic over HTTP/HTTPS, often used in identity management environments. A vulnerability allows an unauthenticated attacker to force the proxy to connect to arbitrary internal servers by providing a specially crafted realm name. This can be used to bypass firewalls, scan internal networks, or access sensitive internal data that is not intended to be exposed to the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in kdcproxy when the 'use_dns' setting is enabled (which is the default). When kdcproxy receives a request for a Kerberos realm that lacks a static configuration, it attempts to discover the Key Distribution Center (KDC) by querying DNS SRV records for that realm. An attacker can provide a realm name they control, pointing the SRV records to internal hostnames or loopback addresses. This allows the attacker to use the proxy as a pivot to probe internal network topology, perform port scanning, or exfiltrate data from internal services. The issue is fixed in kdcproxy version 1.1.0 and various Red Hat package updates.

Affected products

  • latchset kdcproxy < 1.1.0
  • Red Hat Red Hat Enterprise Linux 7/8/9/10 python-kdcproxy < 1.0.0-19.el10_1

Timeline

  • 2025-11-12: disclosed
  • 2025-11-12: advisory
  • 2025-11-12: patched

References

Related threats