CVE-2026-40097
Last modified
CVE-2026-40097 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extension during TPM device attestation. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extension during TPM device attestation. When processing a device-attest-01 ACME challenge using TPM attestation, Step CA validates that the AK certificate contains the tcg-kp-AIKCertificate Extended Key Usage OID. During this validation, the EKU extension value is decoded from its ASN.1 representation and the first element is checked. A crafted certificate could include an EKU extension that decodes to an empty sequence, causing the code to panic when accessing the first element of the empty slice. This vulnerability is only reachable when a device-attest-01 ACME challenge with TPM attestation is configured. Deployments not using TPM device attestation are not affected. This vulnerability is fixed in 0.30.0-rc3.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Smallstep | Step-Ca | >= 0.24.0, < 0.30.0 | — |
| Smallstep | Step-Ca | 0.30.0 | Rc1 |
References
- https://github.com/smallstep/certificates/pull/2569Issue Tracking, Patch
- https://github.com/smallstep/certificates/releases/tag/v0.30.0Product, Release Notes
- https://github.com/smallstep/certificates/security/advisories/GHSA-9qq8-cgcv-qmc9Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-40097?
How severe is CVE-2026-40097?
How do I fix CVE-2026-40097?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40090Zarf is an Airgap Native Packager Manager for Kubernetes. Ve…7.1
- CVE-2026-40091SpiceDB is an open source database system for creating and m…4.4
- CVE-2026-40092nimiq-blockchain provides persistent block storage for Nimiq…7.5
- CVE-2026-40093nimiq-blockchain provides persistent block storage for Nimiq…8.1
- CVE-2026-40094nimiq-blockchain provides persistent block storage for Nimiq…4.3
- CVE-2026-40096immich is a high performance self-hosted photo and video man…5.4
- CVE-2026-40098Magento Long Term Support (LTS) is an unofficial, community-…5.4
- CVE-2026-40099Kirby is an open-source content management system. Kirby's u…6.5
- CVE-2026-4010A vulnerability was found in ThakeeNathees pocketlang up to …3.3
- CVE-2026-40100FastGPT is an AI Agent building platform. Prior to 4.14.10.3…5.3
- CVE-2026-40102Plane is an open-source project management tool. In versions…6.5
- CVE-2026-40103Vikunja is an open-source self-hosted task management platfo…5.4
Are you affected by CVE-2026-40097?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
