PT-2026-54443 · Fulcio · Fulcio
CVE-2026-49478
·
Published
2026-06-30
·
Updated
2026-08-15
CVSS v3.1
8.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fulcio versions prior to 1.8.6
Description
Fulcio improperly handles cross-host redirects and Kubernetes ServiceAccount tokens during OIDC discovery, specifically when fetching metadata from the
/.well-known/openid-configuration endpoint. This leads to three primary issues: first, a malicious issuer can trigger blind Server-Side Request Forgery (SSRF) by redirecting discovery requests to internal systems. Second, an attacker can manipulate the discovery flow to return a malicious jwks uri, allowing them to substitute and poison the verifier cache with malicious JSON Web Key Sets (JWKS) to validate fraudulent signatures. Third, the system may leak Kubernetes ServiceAccount tokens to external hosts if the transport attaches the token globally during redirects or when a wildcard MetaIssuer of type kubernetes matches external endpoints while a local issuer is configured.Recommendations
Update Fulcio to version 1.8.6.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fulcio