Security fixes in tekton-chains 0.25.2-r1 (CVE-2026-49478)
Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...
AI Analysis
Technical Summary
Fulcio, a sigstore component acting as a certificate authority for OIDC-based code signing certificates, suffers from a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in versions before 1.8.6. The vulnerability arises because these versions improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery. This behavior enables a malicious or compromised OIDC issuer to exploit blind SSRF, substitute and cache malicious JSON Web Key Sets (JWKS), or exfiltrate ServiceAccount tokens to external hosts. The issue is addressed in version 1.8.6 by blocking cross-host redirects, restricting token injection, and limiting local token loading.
Potential Impact
Successful exploitation can lead to high impact including disclosure of Kubernetes ServiceAccount tokens, enabling further compromise of Kubernetes environments. Attackers can also perform blind SSRF attacks and substitute malicious JWKS keys, potentially undermining the integrity of code signing certificates issued by fulcio. The vulnerability does not affect availability but compromises confidentiality and integrity.
Mitigation Recommendations
Upgrade fulcio to version 1.8.6 or later, which blocks cross-host redirects, restricts token injection, and limits local token loading to mitigate this vulnerability. No known workarounds are available. Applying the official fix is required to address the issue.
Security fixes in tekton-chains 0.25.2-r1 (CVE-2026-49478)
Description
Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Fulcio, a sigstore component acting as a certificate authority for OIDC-based code signing certificates, suffers from a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in versions before 1.8.6. The vulnerability arises because these versions improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery. This behavior enables a malicious or compromised OIDC issuer to exploit blind SSRF, substitute and cache malicious JSON Web Key Sets (JWKS), or exfiltrate ServiceAccount tokens to external hosts. The issue is addressed in version 1.8.6 by blocking cross-host redirects, restricting token injection, and limiting local token loading.
Potential Impact
Successful exploitation can lead to high impact including disclosure of Kubernetes ServiceAccount tokens, enabling further compromise of Kubernetes environments. Attackers can also perform blind SSRF attacks and substitute malicious JWKS keys, potentially undermining the integrity of code signing certificates issued by fulcio. The vulnerability does not affect availability but compromises confidentiality and integrity.
Mitigation Recommendations
Upgrade fulcio to version 1.8.6 or later, which blocks cross-host redirects, restricts token injection, and limits local token loading to mitigate this vulnerability. No known workarounds are available. Applying the official fix is required to address the issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-f5mr-q85p-6hh6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-49478"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a4452e227e9c797198e1189
Added to database: 06/30/2026, 23:36:02 UTC
Last enriched: 08/13/2026, 19:57:48 UTC
Last updated: 09/13/2026, 10:01:31 UTC
Views: 121
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.