CVE-2025-66406

Publication date

2025-12-03 19:13:48

Family

GitHub_M

State

PUBLISHED

Description

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is fixed in 0.29.0.