Skip to content

Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL

Moderate severity GitHub Reviewed Published Jan 22, 2026 in sigstore/rekor • Updated Jan 22, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts