Security Advisories for github.com/sigstore/fulcio in go
High
about 2 months ago
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
go
github.com/sigstore/fulcio
Moderate
7 months ago
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
go
github.com/sigstore/fulcio
High
8 months ago
Fulcio allocates excessive memory during token parsing
go
github.com/sigstore/fulcio