PT-2025-49168 · Fulcio+1 · Fulcio+1

CVE-2025-66506

·

Published

2025-01-01

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Fulcio versions prior to 1.8.3
Description Fulcio is a certificate authority for issuing code signing certificates for OpenID Connect (OIDC) identity. The identity.extractIssuerURL function splits its input, which is untrusted data, on periods. A malicious request with a large number of period characters in the OIDC identity token payload can cause the function to allocate memory proportional to the input length, potentially leading to excessive memory consumption.
Recommendations Update to version 1.8.3 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-HF07497
CLEANSTART-2026-ZM74354
CVE-2025-66506
ECHO-8C75-2B8F-1138
GHSA-F83F-XPX7-FFPW
GO-2025-4193
OPENSUSE-SU-2026:21483-1
SUSE-SU-2025:4395-1

Affected Products

Debian
Fulcio