github.com/sigstore/fulcio
Sigstore OIDC PKI
Activity
- Latest release
- Jul 07, 2026
- Total releases
- 46
- Cadence
- ~17 days
- Last 12 months
- 9
Reach
- Stars
- 863
Details
- First release
- Jul 26, 2021
| Version | Released | |
|---|---|---|
v1.8.8
patch
|
v1.8.8
patch
Dependencies (42)
+ 34 more |
|
v1.8.7
patch
|
v1.8.7
patch
Dependencies (43)
+ 35 more |
|
v1.8.6
patch
|
v1.8.6
patch
Dependencies (43)
+ 35 more |
|
v1.8.5
patch
1 CVE
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev |
v1.8.5
patch
Dependencies (43)
+ 35 more |
|
v1.8.4
patch
2 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.4
patch
Dependencies (43)
+ 35 more |
|
v1.8.3
patch
2 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.3
patch
Dependencies (43)
+ 35 more |
|
v1.8.2
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.2
patch
Dependencies (43)
+ 35 more |
|
v1.8.1
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.1
patch
Dependencies (43)
+ 35 more |
|
v1.8.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.0
minor
Dependencies (43)
+ 35 more |
|
v1.7.1
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (43)
+ 35 more |
|
v1.7.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (43)
+ 35 more |
|
v1.6.6
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.6
patch
Dependencies (41)
+ 33 more |
|
v1.6.5
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.5
patch
Dependencies (41)
+ 33 more |
|
v1.6.4
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.4
patch
Dependencies (40)
+ 32 more |
|
v1.6.3
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.3
patch
Dependencies (40)
+ 32 more |
|
v1.6.2
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (40)
+ 32 more |
|
v1.6.1
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.1
patch
Dependencies (40)
+ 32 more |
|
v1.6.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (40)
+ 32 more |
|
v1.5.1
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.5.1
patch
Dependencies (40)
+ 32 more |
|
v1.5.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (40)
+ 32 more |
|
v1.4.5
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.5
patch
Dependencies (39)
+ 31 more |
|
v1.4.4
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.4
patch
Dependencies (39)
+ 31 more |
|
v1.4.3
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3
patch
Dependencies (39)
+ 31 more |
|
v1.4.2
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (39)
+ 31 more |
|
v1.4.1
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (39)
+ 31 more |
|
v1.4.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (39)
+ 31 more |
|
v1.3.4
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.4
patch
Dependencies (39)
+ 31 more |
|
v1.3.3
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.3
patch
Dependencies (39)
+ 31 more |
|
v1.3.2
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (39)
+ 31 more |
|
v1.3.1
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.1
patch
Dependencies (35)
+ 27 more |
|
v1.3.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (35)
+ 27 more |
|
v1.2.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (35)
+ 27 more |
|
v1.1.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (35)
+ 27 more |
|
v1.0.0
major
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (34)
+ 26 more |
|
v1.0.0-rc.0
pre
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc.0
pre
Dependencies (34)
+ 26 more |
|
v0.6.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (33)
+ 25 more |
|
v0.5.4
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.4
patch
Dependencies (32)
+ 24 more |
|
v0.5.3
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.3
patch
Dependencies (32)
+ 24 more |
|
v0.5.2
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.2
patch
Dependencies (32)
+ 24 more |
|
v0.5.1
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.1
patch
Dependencies (32)
+ 24 more |
|
v0.5.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (30)
+ 22 more |
|
v0.4.1
patch
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (30)
+ 22 more |
|
v0.4.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (30)
+ 22 more |
|
v0.3.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (24)
+ 16 more |
|
v0.2.0
minor
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (25)
+ 17 more |
|
v0.1.1
initial
3 CVEs
CVE-2026-49478
GO-2026-5853
GHSA-f5mr-q85p-6hh6
Jul 07, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio Fixed in
1.8.6
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-22772
GO-2026-4311
GHSA-59jp-pj84-45mr
Jan 23, 2026
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio Fixed in
1.8.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-66506
GO-2025-4193
GHSA-f83f-xpx7-ffpw
Dec 08, 2025
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio Fixed in
1.8.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.1.1
initial
Dependencies (24)
+ 16 more |