A vulnerability has been found in Sigstore Fulcio up to 1.8.5 and classified as critical. This affects an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-49478. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.