CVE-2025-66406: step-ca Has Improper Authorization Check for SSH Certificate Revocation
(updated )
An authorized attacker can bypass authorization checks and revoke any SSH certificate issued by Step CA by using a valid revocation token.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-66406 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →