CVE-2025-59088
Rocky Linux vulnerability analysis and mitigation

Overview

CVE-2025-59088 is a Server-Side Request Forgery (SSRF) vulnerability discovered in python-kdcproxy. The vulnerability was disclosed on November 12, 2025, affecting kdcproxy when it receives a request for a realm without defined server addresses in its configuration. By default, it queries SRV records in the DNS zone matching the requested realm name (NVD).

Technical details

The vulnerability occurs because kdcproxy allows DNS discovery for any requested realm by querying SRV records from the DNS zone matching the realm name. An attacker could send a request for a realm matching a DNS zone where they created SRV records pointing to arbitrary ports and hostnames, which may resolve to loopback or internal IP addresses. The vulnerability has been assigned a CVSS 3.1 base score of 8.6 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N (Red Hat).

Impact

This vulnerability can be exploited to probe internal network topology and firewall rules, perform port scanning, and exfiltrate data. The attacker could direct requests to any IP addresses, including loopback and internal network addresses, allowing for network reconnaissance and potential data theft (GitHub PR).

Mitigation and workarounds

The vulnerability has been patched by restricting DNS discovery of KDCs to realms explicitly declared in the configuration only. Support for wildcard realm sections (e.g., [*EXAMPLE.COM]) has been added to handle realm hierarchies. Deployments where the 'usedns' setting is explicitly set to false are not affected. The previous unsafe behavior can be restored using the dnsrealm_discovery setting if needed (GitHub PR).

Additional resources


SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13020HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesNov 11, 2025
CVE-2025-59088HIGH8.6
  • Rocky LinuxRocky Linux
  • idm:client::python3-pyusb
NoYesNov 12, 2025
CVE-2025-13019HIGH8.1
  • NixOSNixOS
  • MozillaThunderbird-translations-common
NoYesNov 11, 2025
CVE-2025-13018HIGH8.1
  • NixOSNixOS
  • rhel10::firefox-flatpak
NoYesNov 11, 2025
CVE-2025-59089MEDIUM5.9
  • Rocky LinuxRocky Linux
  • python-qrcode
NoYesNov 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management