<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:45:53 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BA61304 — Security fixes in cosign 2.4.3-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ba61304</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign&lt;/p&gt;
&lt;p&gt;Package cosign version 2.4.3-r0 fixes 82 vulnerabilities: CVE-2025-0913, CVE-2025-15558, CVE-2025-22868, CVE-2025-22869, CVE-2025-22870...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign&lt;/p&gt;
&lt;p&gt;Package cosign version 2.4.3-r0 fixes 82 vulnerabilities: CVE-2025-0913, CVE-2025-15558, CVE-2025-22868, CVE-2025-22869, CVE-2025-22870...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ba61304</guid>
    </item>
    <item>
      <title>EUVD-2026-265491</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265491</link>
      <description>EUVD-2026-265491</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265491</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22772</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22772</link>
      <description>&lt;p&gt;Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio&amp;#39;s metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. This vulnerability is fixed in 1.8.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio&amp;#39;s metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. This vulnerability is fixed in 1.8.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22772</guid>
    </item>
    <item>
      <title>GHSA-59jp-pj84-45mr — Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-59jp-pj84-45mr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sigstore/fulcio&lt;/p&gt;
&lt;p&gt;# Security Disclosure: SSRF via MetaIssuer Regex Bypass&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Fulcio&amp;#39;s `metaRegex()` function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services.&lt;/p&gt;
&lt;p&gt;Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through [Blind SSRF](https://portswigger.net/web-security/ssrf/blind).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- SSRF to cloud metadata (169.254.169.254)
- SSRF to internal Kubernetes APIs
- SSRF to any service accessible from Fulcio&amp;#39;s network
- Affects ALL deployments using MetaIssuers&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to v1.8.5.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;None. If anchors are included in the meta issuer configuration URL, they will be escaped before the regular expression is compiled, not making this a sufficient mitigation. Deployments must upgrade to the latest Fulcio release v1.8.5.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;**File**: `pkg/config/config.go`  
**Function**: `metaRegex()` (lines 143-156)&lt;/p&gt;
&lt;p&gt;```go
func metaRegex(issuer string) (*regexp.Regexp, error) {
    quoted := regexp.QuoteMeta(issuer)
    replaced := strings.ReplaceAll(quoted, regexp.QuoteMeta(&amp;#34;*&amp;#34;), &amp;#34;[-_a-zA-Z0-9]+&amp;#34;)
    return regexp.Compile(replaced)  // Missing ^ and $ anchors
}
```&lt;/p&gt;
&lt;p&gt;## The Bug&lt;/p&gt;
&lt;p&gt;The regex has no `^` (start) or `$` (end) anchors. Go&amp;#39;s `regexp.MatchString()` does substring matching, so:&lt;/p&gt;
&lt;p&gt;```
Patt…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sigstore/fulcio&lt;/p&gt;
&lt;p&gt;# Security Disclosure: SSRF via MetaIssuer Regex Bypass&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Fulcio&amp;#39;s `metaRegex()` function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services.&lt;/p&gt;
&lt;p&gt;Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through [Blind SSRF](https://portswigger.net/web-security/ssrf/blind).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- SSRF to cloud metadata (169.254.169.254)
- SSRF to internal Kubernetes APIs
- SSRF to any service accessible from Fulcio&amp;#39;s network
- Affects ALL deployments using MetaIssuers&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to v1.8.5.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;None. If anchors are included in the meta issuer configuration URL, they will be escaped before the regular expression is compiled, not making this a sufficient mitigation. Deployments must upgrade to the latest Fulcio release v1.8.5.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;**File**: `pkg/config/config.go`  
**Function**: `metaRegex()` (lines 143-156)&lt;/p&gt;
&lt;p&gt;```go
func metaRegex(issuer string) (*regexp.Regexp, error) {
    quoted := regexp.QuoteMeta(issuer)
    replaced := strings.ReplaceAll(quoted, regexp.QuoteMeta(&amp;#34;*&amp;#34;), &amp;#34;[-_a-zA-Z0-9]+&amp;#34;)
    return regexp.Compile(replaced)  // Missing ^ and $ anchors
}
```&lt;/p&gt;
&lt;p&gt;## The Bug&lt;/p&gt;
&lt;p&gt;The regex has no `^` (start) or `$` (end) anchors. Go&amp;#39;s `regexp.MatchString()` does substring matching, so:&lt;/p&gt;
&lt;p&gt;```
Patt…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-59jp-pj84-45mr</guid>
    </item>
    <item>
      <title>openSUSE-RU-2026:20161-1 — Recommended update for hauler</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-ru-2026:20161-1</link>
      <description>&lt;p&gt;Recommended update for hauler&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for hauler&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-ru-2026:20161-1</guid>
    </item>
    <item>
      <title>RHSA-2026:2136 — Red Hat Security Advisory: RHTAS 1.3.2 - Red Hat Trusted Artifact Signer Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:2136</link>
      <description>&lt;p&gt;golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:2136</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0592-1 — Security update for vexctl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0592-1</link>
      <description>&lt;p&gt;Security update for vexctl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for vexctl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0592-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-22772</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22772</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: golang-github-sigstore-fulcio, Ubuntu:26.04:LTS: golang-github-sigstore-fulcio&lt;/p&gt;
&lt;p&gt;Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio&amp;#39;s metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. This vulnerability is fixed in 1.8.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: golang-github-sigstore-fulcio, Ubuntu:26.04:LTS: golang-github-sigstore-fulcio&lt;/p&gt;
&lt;p&gt;Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio&amp;#39;s metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. This vulnerability is fixed in 1.8.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22772</guid>
    </item>
  </channel>
</rss>
