---
id: CVE-2026-24117
title: >-
  github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF)
  (CVE-2026-24117)
summary: >-
  A Server-Side Request Forgery (SSRF) flaw has been discovered in the Rekor
  transparency log tool. In versions 1.4.3 and below, attackers can trigger SSRF
  to arbitrary internal services because /api/v1/index/retrieve supports
  retrieving a p…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cvssSource: vendor
cwe: CWE-918
vendor: Red Hat
product: Red Hat Openshift Data Foundation 4.22
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - confidential_compute_attestation
  - kernel_module_management_operator_for_red_hat_openshift
  - logging_subsystem_for_red_hat_openshift
  - migration_toolkit_for_containers
  - migration_toolkit_for_virtualization
  - multiarch_tuning_operator
  - multicluster_engine_for_kubernetes
  - network_observability_operator
  - node_healthcheck_operator
  - openshift_api_for_data_protection
  - openshift_developer_tools_and_services
  - openshift_pipelines
  - openshift_serverless
  - openshift_service_mesh 2
  - openshift_service_mesh 3
  - pen_drive_powered_by_red_hat_lightspeed
  - power_monitoring_for_red_hat_openshift
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - ansible_automation_platform 2
  - build_of_kueue
  - enterprise_linux 10
  - enterprise_linux 9
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_gitops
  - openstack_platform 18.0
  - quay 3
  - trusted_artifact_signer
  - security_profiles_operator
  - zero_trust_workload_identity_manager
  - zero_trust_workload_identity_manager_tech_preview
  - openshift_data_foundation 4.22
patched:
  - openshift_data_foundation 4.22
published: '2026-01-22'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:23:28+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24117.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24117.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-24117'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2432218'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-24117'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-24117'
  - url: >-
      https://github.com/sigstore/rekor/commit/60ef2bceba192c5bf9327d003bceea8bf1f8275f
  - url: 'https://github.com/sigstore/rekor/releases/tag/v1.5.0'
  - url: 'https://github.com/sigstore/rekor/security/advisories/GHSA-4c4x-jm2x-pf9j'
  - url: 'https://access.redhat.com/errata/RHSA-2026:37387'
  - url: 'https://github.com/sigstore/rekor'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00369
epssPercentile: 0.28063
aliases:
  - GHSA-4c4x-jm2x-pf9j
  - GO-2026-4355
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.752Z'
---

## Overview

A Server-Side Request Forgery (SSRF) flaw has been discovered in the Rekor transparency log tool. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF.

## Vendor advisories

- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)
- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, Migration Toolkit for Containers, Migration Toolkit for Virtualization, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Kernel Module Management Operator for Red Hat Openshift, Logging Subsystem for Red Hat OpenShift, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24117.json)

**github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF)** — rated Moderate by Red Hat. Released 2026-01-22, updated 2026-09-21.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Confidential Compute Attestation
- Kernel Module Management Operator for Red Hat Openshift
- Logging Subsystem for Red Hat OpenShift
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Pen Drive Powered by Red Hat Lightspeed
- Power monitoring for Red Hat OpenShift
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Build of Kueue
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat OpenStack Platform 18.0
- Red Hat Quay 3
- Red Hat Trusted Artifact Signer
- Security Profiles Operator
- Zero Trust Workload Identity Manager
- Zero Trust Workload Identity Manager - Tech Preview

Fixed:

- Red Hat Openshift Data Foundation 4.22

No fix planned:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Confidential Compute Attestation
- Kernel Module Management Operator for Red Hat Openshift
- Logging Subsystem for Red Hat OpenShift
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- Pen Drive Powered by Red Hat Lightspeed
- Power monitoring for Red Hat OpenShift
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Build of Kueue
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat OpenStack Platform 18.0
- Red Hat Quay 3
- Red Hat Trusted Artifact Signer
- Security Profiles Operator
- Zero Trust Workload Identity Manager
- Zero Trust Workload Identity Manager - Tech Preview

Not affected:

- Red Hat Openshift Data Foundation 4.22

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf https://access.redhat.com/errata/RHSA-2026:37387

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2026-24117)

Affected packages:

- `github.com/sigstore/rekor < 1.5.0`

Patched in:

- `github.com/sigstore/rekor 1.5.0`

Source: https://osv.dev/vulnerability/GHSA-4c4x-jm2x-pf9j
