8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/smallstep/certificates is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 10.0
CVE-2026-30836
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
MEDIUM 5.0
CVE-2025-66406
step-ca Has Improper Authorization Check for SSH Certificate Revocation
CRITICAL 10.0
CVE-2025-44005
Step CA Has Authorization Bypass in ACME and SCEP Provisioners
LOW 3.7
CVE-2026-40097
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
UNKNOWN
CVE-2026-40097
Step CA affected by an index out of bounds panic in TPM attestation EKU validation in github.com/smallstep/certificates
UNKNOWN
CVE-2026-30836
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18) in github.com/smallstep/certificates
UNKNOWN
CVE-2025-44005
Step CA Has Authorization Bypass in ACME and SCEP Provisioners in github.com/smallstep/certificates
UNKNOWN
CVE-2025-66406
step-ca Has Improper Authorization Check for SSH Certificate Revocation in github.com/smallstep/certificates
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes