Cross-Host Redirects Affect Fulcio Certificate Authority by Sigstore
CVE-2026-49478
What is CVE-2026-49478?
The Fulcio Certificate Authority from Sigstore is susceptible to vulnerabilities in versions up to 1.8.5, where improper handling of cross-host redirects can lead to significant security risks. Specifically, these versions allow malicious entities to exploit these redirects, resulting in potential blind Server-Side Request Forgery (SSRF), as well as the substitution and caching of malicious JSON Web Key Sets (JWKS). Critically, this flaw may enable attackers to disclose Kubernetes ServiceAccount tokens to unauthorized external hosts. Version 1.8.6 addresses these issues by blocking cross-host redirects, limiting token injection, and preventing local token loading. Users are encouraged to upgrade to this version for enhanced security.
Affected Version(s)
fulcio < 1.8.6
