VDB
Sign up

package

Go/github.com/sigstore/fulcio

pkg:go/github.com/sigstore/fulcio

—Go
GO-2026-5853· CVE-2026-49478, GHSA-f5mr-q85p-6hh6

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio

Modified: 7/10/2026