SSRF Vulnerability in Fulcio Certificate Authority Software
CVE-2026-22772
5.8MEDIUM
What is CVE-2026-22772?
Fulcio, a certificate authority for code signing certificates in OpenID Connect (OIDC) environments, had a vulnerability that allowed attackers to exploit unanchored regex in its metaRegex() function. This flaw enabled bypassing of MetaIssuer URL validation, leading to potential Server-Side Request Forgery (SSRF) attacks targeting arbitrary internal services. While the SSRF could only initiate GET requests without state mutation or data exfiltration, it presented a risk for probing internal network configurations. This vulnerability has been addressed in version 1.8.5.
Affected Version(s)
fulcio < 1.8.5
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
