Smallstep develops a focused infrastructure product—the Step CA certificate-authority platform—that sits in the privileged path of public-key infrastructure and identity management for distributed systems. The recurring vulnerability signal centers on authentication and certificate-validation mechanisms, alongside input-validation issues that can arise in the handling of cryptographic metadata and protocol state. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smallstep over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30836CRITICAL Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certifica | Mar 19, 2026 | 10.0 | 33 | NO | NO |
Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds | Apr 10, 2026 | 3.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smallstep.
Media articles that mention a CVE ID that affects a product developed by Smallstep — matched by CVE ID, not by vendor name.