Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
Modified: 9/10/2026
package
pkg:go/github.com/sigstore/fulcio
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
Modified: 9/10/2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
Modified: 9/10/2026
Fulcio allocates excessive memory during token parsing
Modified: 9/10/2026
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio
Modified: 2/4/2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio
Modified: 2/4/2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio
Modified: 7/10/2026