---
id: CVE-2026-49478
title: >-
  Fulcio is a certificate authority for issuing code signing certificates for an
  OpenID Connect (OIDC) identity
summary: >-
  Fulcio is a certificate authority for issuing code signing certificates for an
  OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow
  cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC
  discover…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-918
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - confidential_compute_attestation
  - kernel_module_management_operator_for_red_hat_openshift
  - lightspeed_core
  - logging_subsystem_for_red_hat_openshift
  - logical_volume_manager_storage
  - migration_toolkit_for_containers
  - migration_toolkit_for_virtualization
  - multiarch_tuning_operator
  - multicluster_engine_for_kubernetes
  - node_healthcheck_operator
  - openshift_api_for_data_protection
  - openshift_developer_tools_and_services
  - openshift_lightspeed
  - openshift_pipelines
  - openshift_serverless
  - openshift_service_mesh 3
  - pen_drive_powered_by_red_hat_lightspeed
  - power_monitoring_for_red_hat_openshift
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - ansible_automation_platform 2
  - developer_hub
  - enterprise_linux 10
  - enterprise_linux 9
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_data_foundation 4
  - openshift_dev_spaces
  - openshift_gitops
  - openshift_virtualization 4
  - openstack_platform 18.0
  - quay 3
  - trusted_artifact_signer
  - security_profiles_operator
  - self_service_automation_portal 2
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
patched:
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
published: '2026-08-13'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:02:22.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49478'
references:
  - url: >-
      https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1
    label: security-advisories@github.com
  - url: 'https://github.com/sigstore/fulcio/pull/2354'
    label: security-advisories@github.com
  - url: 'https://github.com/sigstore/fulcio/releases/tag/v1.8.6'
    label: security-advisories@github.com
  - url: 'https://github.com/sigstore/fulcio/security/advisories/GHSA-f5mr-q85p-6hh6'
    label: security-advisories@github.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49478.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-49478'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2499690'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-49478'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49478'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48872'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48913'
  - url: 'https://github.com/advisories/GHSA-f5mr-q85p-6hh6'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - ghsa
  - go
  - score-dispute
epss: 0.00282
epssPercentile: 0.1835
ecosystem: go
scores:
  nvd: 8.7
  vendor: 6.5
ingestedAt: '2026-06-30T21:24:14.395Z'
---

## Overview

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute and cache malicious JWKS keys, or disclose ServiceAccount tokens to external hosts. Version 1.8.6 blocks cross-host redirects, restricts token injection, and restricts local token loading. No known workarounds are available.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-49478)

Affected packages:

- `github.com/sigstore/fulcio <= 1.8.5`

Patched in:

- `github.com/sigstore/fulcio 1.8.6`

Source: https://github.com/advisories/GHSA-f5mr-q85p-6hh6

## Vendor advisories

- **RHSA-2026:48872** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.9 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48872)
- **RHSA-2026:48913** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.10 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48913)
- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Kernel Module Management Operator for Red Hat Openshift, Lightspeed Core, Logging Subsystem for Red Hat OpenShift, Logical Volume Manager Storage, … · no fix planned: Multicluster Engine for Kubernetes, Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Kernel Module Management Operator for Red Hat Openshift, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49478.json)
