Known vulnerabilities in Fulcio
Vendor:
Sigstore
Software:
Fulcio
Software CPE:
cpe:2.3:a:sigstore:fulcio:*:*:*:*:*:*:*:*
Website:
https://github.com/sigstore/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132352 - Insufficient Verification of Data Authenticity |
CWE-345 | High | 1.8.6 | 27.05.2026 |
SB2026052728 |
||
| #VU132353 - Exposure of sensitive information to an unauthorized actor |
CWE-200 | High | 1.8.6 | 27.05.2026 |
SB2026052728 |
||
| #VU132351 - Server-Side Request Forgery (SSRF) CVE-2026-49478 |
CWE-918 | High | 1.8.6 | 27.05.2026 |
SB2026052728 |
||
| #VU124870 - Server-Side Request Forgery (SSRF) CVE-2026-22772 |
CWE-918 | Medium | 1.8.5 | 06.04.2026 |
SB2026040611 |
||
| #VU119999 - Resource exhaustion CVE-2025-66506 |
CWE-400 | Medium | 1.8.3 | 16.12.2025 |
SB2025121628 SB2025121640 SB2025121641 and 6 more |