PT-2026-54443 · Fulcio · Fulcio

CVE-2026-49478

·

Published

2026-06-30

·

Updated

2026-08-15

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Fulcio versions prior to 1.8.6
Description Fulcio improperly handles cross-host redirects and Kubernetes ServiceAccount tokens during OIDC discovery, specifically when fetching metadata from the /.well-known/openid-configuration endpoint. This leads to three primary issues: first, a malicious issuer can trigger blind Server-Side Request Forgery (SSRF) by redirecting discovery requests to internal systems. Second, an attacker can manipulate the discovery flow to return a malicious jwks uri, allowing them to substitute and poison the verifier cache with malicious JSON Web Key Sets (JWKS) to validate fraudulent signatures. Third, the system may leak Kubernetes ServiceAccount tokens to external hosts if the transport attaches the token globally during redirects or when a wildcard MetaIssuer of type kubernetes matches external endpoints while a local issuer is configured.
Recommendations Update Fulcio to version 1.8.6.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-CP15003
CVE-2026-49478
GHSA-F5MR-Q85P-6HH6
GO-2026-5853
OPENSUSE-SU-2026:21483-1

Affected Products

Fulcio