Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q4r8-xm5f-56gw | step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18) |
Mon, 27 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smallstep step-ca
|
|
| CPEs | cpe:2.3:a:smallstep:step-ca:*:*:*:*:*:go:*:* cpe:2.3:a:smallstep:step-ca:0.30.0:rc1:*:*:*:go:*:* cpe:2.3:a:smallstep:step-ca:0.30.0:rc2:*:*:*:go:*:* cpe:2.3:a:smallstep:step-ca:0.30.0:rc3:*:*:*:go:*:* cpe:2.3:a:smallstep:step-ca:0.30.0:rc4:*:*:*:go:*:* cpe:2.3:a:smallstep:step-ca:0.30.0:rc5:*:*:*:go:*:* cpe:2.3:a:smallstep:step-ca:0.30.0:rc6:*:*:*:go:*:* |
|
| Vendors & Products |
Smallstep step-ca
|
Wed, 25 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 21 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 20 Mar 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smallstep
Smallstep certificates |
|
| Vendors & Products |
Smallstep
Smallstep certificates |
Thu, 19 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0. | |
| Title | Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18) | |
| Weaknesses | CWE-287 CWE-295 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T14:16:09.012Z
Reserved: 2026-03-05T21:06:44.606Z
Link: CVE-2026-30836
Updated: 2026-03-25T14:15:54.392Z
Status : Analyzed
Published: 2026-03-19T21:17:09.783
Modified: 2026-04-27T13:41:54.727
Link: CVE-2026-30836
OpenCVE Enrichment
Updated: 2026-03-25T11:55:00Z
Github GHSA