SSRF Vulnerability in Fulcio Certificate Authority Software
CVE-2026-22772

5.8MEDIUM

Key Information:

Vendor

Sigstore

Status
Vendor
CVE Published:
12 January 2026

What is CVE-2026-22772?

Fulcio, a certificate authority for code signing certificates in OpenID Connect (OIDC) environments, had a vulnerability that allowed attackers to exploit unanchored regex in its metaRegex() function. This flaw enabled bypassing of MetaIssuer URL validation, leading to potential Server-Side Request Forgery (SSRF) attacks targeting arbitrary internal services. While the SSRF could only initiate GET requests without state mutation or data exfiltration, it presented a risk for probing internal network configurations. This vulnerability has been addressed in version 1.8.5.

Affected Version(s)

fulcio < 1.8.5

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.