VYPR
Critical severity10.0GHSA Advisory· Published Dec 17, 2025· Updated Apr 15, 2026

CVE-2025-44005

CVE-2025-44005

Description

An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/smallstep/certificatesGo
< 0.29.00.29.0

Affected products

11

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.