Affected by GO-2025-4193
and 2 other vulnerabilities
GO-2025-4193: Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio
GO-2026-4311: Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio
GO-2026-5853: Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage in github.com/sigstore/fulcio