github.com/smallstep/certificates: github.com/smallstep/certificates: Authorization bypass allows unauthorized certificate creation
Published Dec 17, 2025
10.0
CRITICALCVSS 3.1
EPSS 9.09%
Description
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.
Affected products
-
- Version 0.28.4StatusaffectedConstraints-
- Version v0.28.3StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/smallstep/certificates
Go
Introduced 0 Fixed 0.29.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/smallstep/certificates | 0 | 0.29.0 |
Remediation
Red Hat statement
No Red Hat products are impacted, because the affected component (Step CA) is not used or provided by any products. This vulnerability was marked as a Critical vulnerability because it allows a remote, unauthenticated attacker to bypass core authorization mechanisms of a Certificate Authority and directly issue trusted certificates, fundamentally breaking the CA trust boundary. While the flaw does not lead to arbitrary code execution on the Step CA host, compromising a CA’s issuance process is equivalent to a system-level security failure, as attackers can mint certificates for unauthorized identities and use them for large-scale impersonation, man-in-the-middle attacks, and interception of encrypted traffic across systems beyond the CA itself. The attack requires no privileges, no user interaction, and low complexity, and its effects propagate outside the vulnerable system due to the implicit trust placed in issued certificates, resulting in a scope change and high confidentiality and integrity impact. This ability to undermine PKI trust at scale elevates the flaw beyond an Important issue and justifies a Critical severity classification from a technical risk standpoint.
Red Hat mitigation
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. But the exposure can be minimized by restricting or blocking access to the /sign endpoint through network controls or reverse proxies.
References (10)
- https://access.redhat.com/security/cve/CVE-2025-44005 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2423196 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201012 Advisory
- https://github.com/advisories/GHSA-h8cp-697h-8c8p Advisory
- https://github.com/smallstep/certificates/commit/1011f5f5408b470a636f583bf74c0d7bbaf75d72
- https://github.com/smallstep/certificates/security/advisories/GHSA-h8cp-697h-8c8p
- https://nvd.nist.gov/vuln/detail/CVE-2025-44005
- https://talosintelligence.com/vulnerability_reports/TALOS-2025-2242
- https://www.cve.org/CVERecord?id=CVE-2025-44005
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2242
Change history (0)
No recorded changes yet.