Server-Side Request Forgery (SSRF) in Fulcio - #VU153372

 

Server-Side Request Forgery (SSRF) in Fulcio - #VU153372

Published: October 6, 2026


Vulnerability identifier: #VU153372
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to probe internal network services through blind server-side request forgery.

The vulnerability exists due to insufficient validation of JWKS endpoint URLs in the OIDC identity verification path when verifying identities through configured meta issuers. A remote attacker can supply a JWKS URL through an attacker-controlled OIDC discovery endpoint accepted by a meta issuer wildcard pattern to probe internal network services through blind server-side request forgery.

Exploitation permits only GET requests and does not return responses to the requester. Reachable targets can include internal cloud metadata endpoints and internal Kubernetes APIs.


Affected software

Fulcio

Remediation

Install security update from vendor's website.

Fulcio - update to 1.9.0

External References

Related Security Bulletins