Executive brief
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio
Affected products
- Go github.com/sigstore/fulcio
Junglewise Threat Intelligence
CVE-2026-22772 · Severity: low · CVSS 3.1 · Published 2026-01-23
Technologies: github.com/sigstore/fulcio (Go). Vendors: Go.
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio