Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49478

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in Fulcio's OpenID Connect (OIDC) Discovery client. This vulnerability allows a remote attacker to perform Server-Side Request Forgery (SSRF) by redirecting discovery requests to internal systems. Additionally, an attacker can manipulate the JSON Web Key Set (JWKS) Uniform Resource Identifier (URI) to poison the verifier cache with malicious keys, enabling the validation of attacker-controlled signatures. Furthermore, the flaw can lead to the leakage of Kubernetes ServiceAccount tokens to third-party hosts through cross-host redirects or misconfigured MetaIssuers, potentially exposing sensitive cluster credentials.

Отчет

A flaw was found in Fulcio's OIDC Discovery client. Three related vulnerabilities allow exploitation when a configured OIDC issuer is compromised or malicious: (1) Blind SSRF — the discovery client follows cross-host HTTP redirects, allowing a malicious issuer to redirect Fulcio's metadata fetch requests to internal-only systems (e.g., cloud IMDS endpoints, RFC 1918 addresses); (2) JWKS substitution — the redirected discovery flow can return a manipulated jwks_uri pointing to an attacker-controlled host, poisoning the verifier cache with attacker keys and enabling validation of attacker-controlled signatures; (3) Kubernetes ServiceAccount token leakage — the in-cluster SA token is attached globally by the HTTP transport, leaking it to third-party hosts during cross-host redirects or when wildcard MetaIssuers match external endpoints. Exploitation requires a compromised or malicious OIDC issuer already trusted in the Fulcio configuration. In typical Red Hat Trusted Artifact Signer deployments, OIDC issuers are explicitly configured and curated, reducing the attack surface."}]

Меры по смягчению последствий

Upgrade to Fulcio v1.8.6 or later. No workaround is available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
Assisted Installer for Red Hat OpenShift Container Platform 2fulcioNot affected
Confidential Compute AttestationfulcioNot affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-must-gather-rhel9Affected
Kernel Module Management Operator for Red Hat OpenshiftfulcioNot affected
Kernel Module Management Operator for Red Hat Openshiftkmm/kernel-module-management-must-gather-rhel9Affected
Lightspeed CorefulcioNot affected
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Affected
Logging Subsystem for Red Hat OpenShiftfulcioNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2499690github.com/sigstore/fulcio: Fulcio: Server-Side Request Forgery and Kubernetes ServiceAccount token leakage

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.7
github
около 1 месяца назад

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

6.5 Medium

CVSS3