Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass in github.com/sigstore/fulcio
{ "url": "https://pkg.go.dev/vuln/GO-2026-4311", "review_status": "UNREVIEWED" }
"https://vuln.go.dev/ID/GO-2026-4311.json"