CVE-2025-66506 | sigstore fulcio up to 1.8.2 OpenID Connect amplification (GHSA-f83f-xpx7-ffpw)
A vulnerability marked as critical has been reported in sigstore fulcio up to 1.8.2. Affected by this issue is some unknown functionality of the component OpenID Connect. Performing manipulation results in asymmetric resource consumption.
This vulnerability is identified as CVE-2025-66506. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.