SB2026100658 - Multiple vulnerabilities in Fulcio



SB2026100658 - Multiple vulnerabilities in Fulcio

Published: October 6, 2026

Security Bulletin ID SB2026100658
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote attacker to probe internal network services through blind server-side request forgery.

The vulnerability exists due to insufficient validation of JWKS endpoint URLs in the OIDC identity verification path when verifying identities through configured meta issuers. A remote attacker can supply a JWKS URL through an attacker-controlled OIDC discovery endpoint accepted by a meta issuer wildcard pattern to probe internal network services through blind server-side request forgery.

Exploitation permits only GET requests and does not return responses to the requester. Reachable targets can include internal cloud metadata endpoints and internal Kubernetes APIs.


Remediation

Install update from vendor's website.