SB2026100658 - Multiple vulnerabilities in Fulcio
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
The vulnerability allows a remote attacker to probe internal network services through blind server-side request forgery.
The vulnerability exists due to insufficient validation of JWKS endpoint URLs in the OIDC identity verification path when verifying identities through configured meta issuers. A remote attacker can supply a JWKS URL through an attacker-controlled OIDC discovery endpoint accepted by a meta issuer wildcard pattern to probe internal network services through blind server-side request forgery.
Exploitation permits only GET requests and does not return responses to the requester. Reachable targets can include internal cloud metadata endpoints and internal Kubernetes APIs.
Remediation
Install update from vendor's website.