SSRF Vulnerability in Rekor Software Supply Chain Transparency Log
CVE-2026-24117

5.3MEDIUM

Key Information:

Vendor

Sigstore

Status
Vendor
CVE Published:
22 January 2026

What is CVE-2026-24117?

In Rekor versions 1.4.3 and earlier, a Server-Side Request Forgery (SSRF) vulnerability exists in the /api/v1/index/retrieve endpoint. This allows attackers to make arbitrary GET requests to internal services through user-supplied URLs. Although the SSRF does not allow state mutation or data exfiltration since the response is not returned to the caller, it may enable attackers to probe internal networks. This risk is mitigated in version 1.5.0, where users are advised to disable the search endpoint by setting --enable_retrieve_api=false as an immediate workaround.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

rekor < 1.5.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.