CVE-2025-44005: Smallstep Step-Ca

Critical severity, CVSS 10.0. EPSS: 9.1% chance of exploitation in the next 30 days.

An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.

Affected products

  • Smallstep Step-Ca: version 0.28.4 only; version v0.28.3 only

Published 2025-12-17. Last modified 2026-06-17.