Skip to main content
EPSS 0.2%top 93%

Security fixes in tekton-chains 0.25.2-r1 (CVE-2026-49478)

0
High
Published: 09/01/2026 (09/01/2026, 11:17:16 UTC)
Source: GCVE Database
Product: cosign

Description

Package tekton-chains version 0.25.2-r1 fixes 23 vulnerabilities: ghsa-gcjh-h69q-9w9g, ghsa-pmwq-pjrm-6p5r, CVE-2026-49478, CVE-2026-48702, CVE-2026-49834...

Affected software

Goghsa
github.com/sigstore/fulcio
Affected versions
<1.8.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 19:57:48 UTC

Technical Analysis

Fulcio, a sigstore component acting as a certificate authority for OIDC-based code signing certificates, suffers from a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in versions before 1.8.6. The vulnerability arises because these versions improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery. This behavior enables a malicious or compromised OIDC issuer to exploit blind SSRF, substitute and cache malicious JSON Web Key Sets (JWKS), or exfiltrate ServiceAccount tokens to external hosts. The issue is addressed in version 1.8.6 by blocking cross-host redirects, restricting token injection, and limiting local token loading.

Potential Impact

Successful exploitation can lead to high impact including disclosure of Kubernetes ServiceAccount tokens, enabling further compromise of Kubernetes environments. Attackers can also perform blind SSRF attacks and substitute malicious JWKS keys, potentially undermining the integrity of code signing certificates issued by fulcio. The vulnerability does not affect availability but compromises confidentiality and integrity.

Mitigation Recommendations

Upgrade fulcio to version 1.8.6 or later, which blocks cross-host redirects, restricts token injection, and limits local token loading to mitigate this vulnerability. No known workarounds are available. Applying the official fix is required to address the issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-f5mr-q85p-6hh6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-49478"]
Ecosystems
["Go"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a4452e227e9c797198e1189

Added to database: 06/30/2026, 23:36:02 UTC

Last enriched: 08/13/2026, 19:57:48 UTC

Last updated: 09/13/2026, 10:01:31 UTC

Views: 121

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses