CVE-2025-66406: step-ca Has Improper Authorization Check for SSH Certificate Revocation
(updated )
A security fix is now available for Step CA that resolves a vulnerability affecting deployments configured with the SSHPOP provisioner.
All operators running these provisioners should upgrade to the latest release (v0.29.0) immediately.
The issue was discovered and responsibly disclosed by a research team during a security review. There is no evidence of active exploitation.
To limit exploitation risk during a coordinated disclosure window, we are withholding detailed technical information for now. A full write-up will be published in several weeks.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-66406 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →