Vulnerability Details CVE-2025-66506
Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request with an (invalid) OIDC identity token in the payload containing many period characters, a call to extractIssuerURL incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This vulnerability is fixed in 1.8.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.1%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-66506
-
cpe:2.3:a:linuxfoundation:fulcio:0.1.0
-
cpe:2.3:a:linuxfoundation:fulcio:0.1.1
-
cpe:2.3:a:linuxfoundation:fulcio:0.2.0
-
cpe:2.3:a:linuxfoundation:fulcio:0.3.0
-
cpe:2.3:a:linuxfoundation:fulcio:0.4.0
-
cpe:2.3:a:linuxfoundation:fulcio:0.4.1
-
cpe:2.3:a:linuxfoundation:fulcio:0.5.0
-
cpe:2.3:a:linuxfoundation:fulcio:0.5.1
-
cpe:2.3:a:linuxfoundation:fulcio:0.5.2
-
cpe:2.3:a:linuxfoundation:fulcio:0.5.3
-
cpe:2.3:a:linuxfoundation:fulcio:0.5.4
-
cpe:2.3:a:linuxfoundation:fulcio:0.6.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.0.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.1.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.2.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.3.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.3.1
-
cpe:2.3:a:linuxfoundation:fulcio:1.3.2
-
cpe:2.3:a:linuxfoundation:fulcio:1.3.3
-
cpe:2.3:a:linuxfoundation:fulcio:1.3.4
-
cpe:2.3:a:linuxfoundation:fulcio:1.4.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.4.1
-
cpe:2.3:a:linuxfoundation:fulcio:1.4.2
-
cpe:2.3:a:linuxfoundation:fulcio:1.4.3
-
cpe:2.3:a:linuxfoundation:fulcio:1.4.4
-
cpe:2.3:a:linuxfoundation:fulcio:1.4.5
-
cpe:2.3:a:linuxfoundation:fulcio:1.5.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.5.1
-
cpe:2.3:a:linuxfoundation:fulcio:1.6.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.6.1
-
cpe:2.3:a:linuxfoundation:fulcio:1.6.2
-
cpe:2.3:a:linuxfoundation:fulcio:1.6.3
-
cpe:2.3:a:linuxfoundation:fulcio:1.6.4
-
cpe:2.3:a:linuxfoundation:fulcio:1.6.5
-
cpe:2.3:a:linuxfoundation:fulcio:1.6.6
-
cpe:2.3:a:linuxfoundation:fulcio:1.7.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.7.1
-
cpe:2.3:a:linuxfoundation:fulcio:1.8.0
-
cpe:2.3:a:linuxfoundation:fulcio:1.8.1
-
cpe:2.3:a:linuxfoundation:fulcio:1.8.2