Cross-Host Redirects Affect Fulcio Certificate Authority by Sigstore
CVE-2026-49478

8.7HIGH

Key Information:

Vendor

Sigstore

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-49478?

The Fulcio Certificate Authority from Sigstore is susceptible to vulnerabilities in versions up to 1.8.5, where improper handling of cross-host redirects can lead to significant security risks. Specifically, these versions allow malicious entities to exploit these redirects, resulting in potential blind Server-Side Request Forgery (SSRF), as well as the substitution and caching of malicious JSON Web Key Sets (JWKS). Critically, this flaw may enable attackers to disclose Kubernetes ServiceAccount tokens to unauthorized external hosts. Version 1.8.6 addresses these issues by blocking cross-host redirects, limiting token injection, and preventing local token loading. Users are encouraged to upgrade to this version for enhanced security.

Affected Version(s)

fulcio < 1.8.6

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.