PT-2025-49168 · Fulcio+1 · Fulcio+1
Published
2025-01-01
·
Updated
2026-05-18
·
CVE-2025-66506
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Fulcio versions prior to 1.8.3
Description
Fulcio is a certificate authority for issuing code signing certificates for OpenID Connect (OIDC) identity. The
identity.extractIssuerURL function splits its input, which is untrusted data, on periods. A malicious request with a large number of period characters in the OIDC identity token payload can cause the function to allocate memory proportional to the input length, potentially leading to excessive memory consumption.Recommendations
Update to version 1.8.3 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Fulcio