Fulcio
This hub aggregates every CVE we track for Fulcio, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
0
0
0
0
1
0
2024-102026-09
Latest CVEs
The 3 most recently published vulnerabilities affecting Fulcio.
- CVE-2026-49478Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage8.7
- CVE-2026-22772Fulcio vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass5.8
- CVE-2025-66506Fulcio allocates excessive memory during token parsing7.5
Product normalization is registry-driven with AI assist and human review. How it works