Fedora Account System
Red Hat Associate
Red Hat Customer
Three vulnerabilities in Fulcio's OIDC Discovery client: (1) Blind SSRF via cross-host redirects during discovery metadata fetch, (2) JWKS substitution and cache poisoning via manipulated jwks_uri pointing to attacker-controlled host, (3) Kubernetes ServiceAccount token leakage to third-party hosts via cross-host redirects or wildcard MetaIssuers. No workaround available. Fixed in Fulcio v1.8.6.