CVE-2025-44005: Smallstep Step-Ca
Critical severity, CVSS 10.0. EPSS: 9.1% chance of exploitation in the next 30 days.
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.
Affected products
- Smallstep Step-Ca: version 0.28.4 only; version v0.28.3 only
Published 2025-12-17. Last modified 2026-06-17.