Threats Tagged 'cve-2025-59088'
View all threats tagged with 'cve-2025-59088'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-59088'
Click on any threat for detailed analysis and mitigation recommendations
0 Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python-kdcproxy: Unauthenticated SSRF via Realm?Controlled DNS SRV (CVE-2025-59088) * python-kdcproxy: Remote DoS via unbounded TCP upstream buffering (CVE-2025-59089) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 12/09/2025, 22:26:17 UTC Added: 06/28/2026, 22:14:00 UTC |
0 Red Hat Identity Management (IdM) has security vulnerabilities in the python-kdcproxy component, including an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records (CVE-2025-59088) and a remote Denial of Service (DoS) via unbounded TCP upstream buffering (CVE-2025-59089). These issues affect Red Hat Enterprise Linux 8.6 variants. Red Hat has issued an important security update to address these vulnerabilities. Join the discussion | GCVE Database | 11/20/2025, 08:18:01 UTC Added: 06/28/2026, 22:14:03 UTC |
0 Red Hat Identity Management (IdM) has security vulnerabilities in the python-kdcproxy component, including an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records (CVE-2025-59088) and a remote Denial of Service (DoS) via unbounded TCP upstream buffering (CVE-2025-59089). These issues affect Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service. Red Hat has released an important security update to address these vulnerabilities. Join the discussion | GCVE Database | 11/20/2025, 08:15:13 UTC Added: 06/28/2026, 22:14:03 UTC |
0 Red Hat Identity Management (IdM) for Red Hat Enterprise Linux 8.2 contains two security vulnerabilities in the python-kdcproxy component. The first is an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote Denial of Service (DoS) caused by unbounded TCP upstream buffering (CVE-2025-59089). These issues have been addressed in an important security update released by Red Hat. The update is available for Red Hat Enterprise Linux Server AUS 8.2 x86_64. No CVSS scores are provided, but the vendor rates the impact as important. No known exploits in the wild have been reported. Join the discussion | GCVE Database | 11/20/2025, 08:05:06 UTC Added: 06/28/2026, 22:14:02 UTC |
0 Two security vulnerabilities have been identified in the python-kdcproxy component of Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The first is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote Denial of Service (DoS) vulnerability caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues for multiple architectures including x86_64, ppc64le, aarch64, and s390x. Users of affected Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions should apply the update to mitigate these vulnerabilities. Join the discussion | GCVE Database | 11/20/2025, 05:58:44 UTC Added: 06/28/2026, 22:14:03 UTC |
0 Two security vulnerabilities have been identified in the python-kdcproxy component of Red Hat Enterprise Linux 9.4 Extended Update Support. The first is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote denial-of-service (DoS) vulnerability caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues for multiple architectures and variants of RHEL 9.4. Join the discussion | GCVE Database | 11/19/2025, 08:16:29 UTC Added: 06/28/2026, 22:14:03 UTC |
0 Two security vulnerabilities were identified in the python-kdcproxy component of Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. The first is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability via realm-controlled DNS SRV records (CVE-2025-59088). The second is a remote Denial of Service (DoS) vulnerability caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues for multiple architectures and lifecycle variants of RHEL 9.2. Join the discussion | GCVE Database | 11/17/2025, 06:19:12 UTC Added: 06/28/2026, 22:14:03 UTC |
0 Red Hat Identity Management (IdM) for Red Hat Enterprise Linux 8 has security vulnerabilities in the python-kdcproxy component. These include an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records (CVE-2025-59088) and a remote denial of service (DoS) caused by unbounded TCP upstream buffering (CVE-2025-59089). Red Hat has released an important security update addressing these issues. Join the discussion | GCVE Database | 11/12/2025, 18:01:16 UTC Added: 06/28/2026, 22:14:04 UTC |
If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. This creates a server-side request forgery vulnerability, since an attacker could send a request for a realm matching a DNS zone where they created SRV records pointing to arbitrary ports and hostnames (which may resolve to loopback or internal IP addresses). This vulnerability can be exploited to probe internal network topology and firewall rules, perform port scanning, and exfiltrate data. Deployments where the "use_dns" setting is explicitly set to false are not affected. Join the discussion | CVE Database V5 | 11/12/2025, 16:35:27 UTC Added: 11/12/2025, 17:17:39 UTC |
0 Two security vulnerabilities were identified in python-kdcproxy, a Python module used in Red Hat Enterprise Linux 9.6 Extended Update Support. The first vulnerability (CVE-2025-59088) is an unauthenticated Server-Side Request Forgery (SSRF) via realm-controlled DNS SRV records. The second (CVE-2025-59089) is a remote denial-of-service (DoS) caused by unbounded TCP upstream buffering. Red Hat has issued an important security update addressing these issues for multiple architectures and variants of RHEL 9.6. Join the discussion | GCVE Database | 11/12/2025, 16:32:24 UTC Added: 06/28/2026, 22:14:04 UTC |
Showing 1 to 10 of 13 results