SSRF Vulnerability in Fulcio Certificate Authority Software
CVE-2026-22772
5.8MEDIUM
What is CVE-2026-22772?
Fulcio, a certificate authority for code signing certificates in OpenID Connect (OIDC) environments, had a vulnerability that allowed attackers to exploit unanchored regex in its metaRegex() function. This flaw enabled bypassing of MetaIssuer URL validation, leading to potential Server-Side Request Forgery (SSRF) attacks targeting arbitrary internal services. While the SSRF could only initiate GET requests without state mutation or data exfiltration, it presented a risk for probing internal network configurations. This vulnerability has been addressed in version 1.8.5.
Affected Version(s)
fulcio < 1.8.5
