{"id":"CVE-2026-24117","title":"github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) (CVE-2026-24117)","summary":"A Server-Side Request Forgery (SSRF) flaw has been discovered in the Rekor transparency log tool. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a p…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cvssSource":"vendor","cwe":"CWE-918","vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.22","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","confidential_compute_attestation","kernel_module_management_operator_for_red_hat_openshift","logging_subsystem_for_red_hat_openshift","migration_toolkit_for_containers","migration_toolkit_for_virtualization","multiarch_tuning_operator","multicluster_engine_for_kubernetes","network_observability_operator","node_healthcheck_operator","openshift_api_for_data_protection","openshift_developer_tools_and_services","openshift_pipelines","openshift_serverless","openshift_service_mesh 2","openshift_service_mesh 3","pen_drive_powered_by_red_hat_lightspeed","power_monitoring_for_red_hat_openshift","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 4","ansible_automation_platform 2","build_of_kueue","enterprise_linux 10","enterprise_linux 9","openshift_ai_rhoai","openshift_container_platform 4","openshift_gitops","openstack_platform 18.0","quay 3","trusted_artifact_signer","security_profiles_operator","zero_trust_workload_identity_manager","zero_trust_workload_identity_manager_tech_preview","openshift_data_foundation 4.22"],"patched":["openshift_data_foundation 4.22"],"published":"2026-01-22","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:23:28+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24117.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24117.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-24117"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2432218"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-24117"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24117"},{"url":"https://github.com/sigstore/rekor/commit/60ef2bceba192c5bf9327d003bceea8bf1f8275f"},{"url":"https://github.com/sigstore/rekor/releases/tag/v1.5.0"},{"url":"https://github.com/sigstore/rekor/security/advisories/GHSA-4c4x-jm2x-pf9j"},{"url":"https://access.redhat.com/errata/RHSA-2026:37387"},{"url":"https://github.com/sigstore/rekor"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00369,"epssPercentile":0.27973,"aliases":["GHSA-4c4x-jm2x-pf9j","GO-2026-4355"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.752Z","slug":"CVE-2026-24117","body":"## Overview\n\nA Server-Side Request Forgery (SSRF) flaw has been discovered in the Rekor transparency log tool. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF.\n\n## Vendor advisories\n\n- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, Migration Toolkit for Containers, Migration Toolkit for Virtualization, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24117.json)\n\n**github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF)** — rated Moderate by Red Hat. Released 2026-01-22, updated 2026-09-21.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Confidential Compute Attestation\n- Kernel Module Management Operator for Red Hat Openshift\n- Logging Subsystem for Red Hat OpenShift\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- Pen Drive Powered by Red Hat Lightspeed\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ansible Automation Platform 2\n- Red Hat Build of Kueue\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift GitOps\n- Red Hat OpenStack Platform 18.0\n- Red Hat Quay 3\n- Red Hat Trusted Artifact Signer\n- Security Profiles Operator\n- Zero Trust Workload Identity Manager\n- Zero Trust Workload Identity Manager - Tech Preview\n\nFixed:\n\n- Red Hat Openshift Data Foundation 4.22\n\nNo fix planned:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Confidential Compute Attestation\n- Kernel Module Management Operator for Red Hat Openshift\n- Logging Subsystem for Red Hat OpenShift\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- Pen Drive Powered by Red Hat Lightspeed\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ansible Automation Platform 2\n- Red Hat Build of Kueue\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift GitOps\n- Red Hat OpenStack Platform 18.0\n- Red Hat Quay 3\n- Red Hat Trusted Artifact Signer\n- Security Profiles Operator\n- Zero Trust Workload Identity Manager\n- Zero Trust Workload Identity Manager - Tech Preview\n\nNot affected:\n\n- Red Hat Openshift Data Foundation 4.22\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf https://access.redhat.com/errata/RHSA-2026:37387\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-24117)\n\nAffected packages:\n\n- `github.com/sigstore/rekor < 1.5.0`\n\nPatched in:\n\n- `github.com/sigstore/rekor 1.5.0`\n\nSource: https://osv.dev/vulnerability/GHSA-4c4x-jm2x-pf9j","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}