CVE-2026-49478High· 8.7▾ TwilightFulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discover…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
8.7 → 6.5
high → medium
6.5 → 8.7
medium → high
8.7 → 6.5
high → medium
6.5 → 8.7
medium → high
8.7 → 6.5
high → medium
6.5 → 8.7
medium → high
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute and cache malicious JWKS keys, or disclose ServiceAccount tokens to external hosts. Version 1.8.6 blocks cross-host redirects, restricts token injection, and restricts local token loading. No known workarounds are available.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/sigstore/fulcio <= 1.8.5Patched in:
github.com/sigstore/fulcio 1.8.6Source: https://github.com/advisories/GHSA-f5mr-q85p-6hh6
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50151Medium· 5.9oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)
CVE-2022-23526High· 7.5helm: Denial of service through schema file (CVE-2022-23526)
CVE-2026-39833Medium· 5.5golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation (CVE-2026-39833)
CVE-2026-39834Medium· 6.5golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write (CVE-2026-39834)
CVE-2026-80950Medium· 5.5kernel: i3c: renesas: Check that the transfer is valid before accessing it (CVE-2026-80950)
CVE-2026-80953Medium· 5.5kernel: i3c: master: adi: initialize the lock before enabling interrupts (CVE-2026-80953)