Server-Side Request Forgery (SSRF) in Fulcio - #VU153372
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to probe internal network services through blind server-side request forgery.
The vulnerability exists due to insufficient validation of JWKS endpoint URLs in the OIDC identity verification path when verifying identities through configured meta issuers. A remote attacker can supply a JWKS URL through an attacker-controlled OIDC discovery endpoint accepted by a meta issuer wildcard pattern to probe internal network services through blind server-side request forgery.
Exploitation permits only GET requests and does not return responses to the requester. Reachable targets can include internal cloud metadata endpoints and internal Kubernetes APIs.