VDB

GO-2026-4355

GO-2026-4355 PUBLISHED CVSS 8.699999809265137 HIGH

Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL in github.com/sigstore/rekor

Risk Scores

CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:L/SA:N

Affected Products

VendorProductVersions
wolfikyverno-1.160, 0, 0
wolficosign0, 0, 0
chainguardbuildkitd-fips0, 0, 0
chainguardteleport-18.60, 0, 0
chainguardgh0, 0, 0
wolfizot0, 0, 0
chainguardcloudbeat-9.20, 0, 0
chainguardbuildkitd0, 0, 0
chainguardcrossplane-2.00, 0, 0
chainguardcloudbeat-8.170, 0, 0
wolfislsa-verifier0, 0, 0
chainguardslsa-verifier0, 0, 0
github.comsigstore/rekor0, 0
chainguardcloudbeat-9.10, 0, 0
wolfiteleport-18.60, 0, 0
chainguardcloudbeat-8.190, 0, 0
chainguardcrossplane-fips-2.10, 0, 0
chainguardkyverno-fips-1.160, 0, 0
chainguardcosign-fips0, 0, 0
chainguardkyverno-fips-1.150, 0, 0

…and 81 more

Timeline

  • Feb 2, 2026 CVE Published
  • Feb 4, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›