Back

CRITICAL

github.com/smallstep/certificates: github.com/smallstep/certificates: Authorization bypass allows unauthorized certificate creation

Published Dec 17, 2025

Description

An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.

Affected products

Remediation

Red Hat statement

No Red Hat products are impacted, because the affected component (Step CA) is not used or provided by any products. This vulnerability was marked as a Critical vulnerability because it allows a remote, unauthenticated attacker to bypass core authorization mechanisms of a Certificate Authority and directly issue trusted certificates, fundamentally breaking the CA trust boundary. While the flaw does not lead to arbitrary code execution on the Step CA host, compromising a CA’s issuance process is equivalent to a system-level security failure, as attackers can mint certificates for unauthorized identities and use them for large-scale impersonation, man-in-the-middle attacks, and interception of encrypted traffic across systems beyond the CA itself. The attack requires no privileges, no user interaction, and low complexity, and its effects propagate outside the vulnerable system due to the implicit trust placed in issued certificates, resulting in a scope change and high confidentiality and integrity impact. This ability to undermine PKI trust at scale elevates the flaw beyond an Important issue and justifies a Critical severity classification from a technical risk standpoint.

Red Hat mitigation

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. But the exposure can be minimized by restricting or blocking access to the /sign endpoint through network controls or reverse proxies.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Dec 17, 2025
Updated Dec 17, 2025
Reserved Jul 28, 2025
CISA Vulnrichment
Updated Dec 17, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Dec 17, 2025
ENISA EUVD
Assigner talos
Published Dec 17, 2025
Updated Dec 17, 2025
Exploited since n/a
EUVD-2025-201012 GHSA-H8CP-697H-8C8P