CVE-2025-44005: Critical severity go/github.com/smallstep/certificates vulnerability
Summary
A security fix is now available for Step CA that resolves a vulnerability affecting deployments configured with ACME and/or SCEP provisioners. All operators running these provisioners should upgrade to the latest release (v0.29.0) immediately.
The issue was discovered and disclosed by a research team during a security review. There is no evidence of active exploitation.
To limit exploitation risk during a coordinated disclosure window, we are withholding detailed technical information for now. A full write-up will be published in several weeks.
---
Embargo List
If your organization runs Step CA in production and would like advance, embargoed notification of future security updates, visit https://u.step.sm/disclosure to request inclusion on our embargo list.
---
Acknowledgements
This issue was identified and reported by Stephen Kubik of the Cisco Advanced Security Initiatives Group (ASIG)
---
Stay safe, and thank you for helping us keep the ecosystem secure.
Other sources
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44005?
CVE-2025-44005 has been assessed as a critical vulnerability affecting Step CA deployments with ACME and SCEP provisioners.
How do I fix CVE-2025-44005?
To resolve CVE-2025-44005, operators must upgrade to Step CA version v0.29.0 immediately.
What are the affected versions for CVE-2025-44005?
CVE-2025-44005 affects versions up to and including v0.28.4 of the Step CA software.
Who disclosed CVE-2025-44005?
CVE-2025-44005 was discovered and disclosed by security researchers working with the Step CA project.
What should I do if I'm using a version prior to v0.29.0?
If you're using a version prior to v0.29.0, you should upgrade immediately to mitigate the risks associated with CVE-2025-44005.