CVE-2026-40097Disclosure(smallstep / step-ca)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extension during TPM device attestation. When processing a device-attest-01 ACME challenge using TPM attestation, Step CA validates that the AK certificate contains the tcg-kp-AIKCertificate Extended Key Usage OID. During this validation, the EKU extension value is decoded from its ASN.1 representation and the first element is checked. A crafted certificate could include an EKU extension that decodes to an empty sequence, causing the code to panic when accessing the first element of the empty slice. This vulnerability is only reachable when a device-attest-01 ACME challenge with TPM attestation is configured. Deployments not using TPM device attestation are not affected. This vulnerability is fixed in 0.30.0-rc3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • step-ca

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
step-ca

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-28: 104-1004-1104-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-101
General1
2026-04-111
Disclosure1
2026-04-281
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-40097 Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index… https://www.cve.org/CVERecord?id=CVE-2026-40097

    Post summary

    The post notes a CVE for Step CA where versions 0.24.0 to before 0.30.0-rc3 may allow an attacker to trigger an index, but it does not provide PoC, exploitation code, patch details, or evidence of active exploitation.

    00010114
    57.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40097: CVE-2026-40097: Index Out-of-Bounds Panic in Step CA TPM Attestation Step CA versions prior to 0.30.0-rc3 contain a vulnerability (CWE-129) where processing a malformed TPM Attestation Key certificate results in a Go runtime panic. Thi... https://cvereports.com/reports/CVE-2026-40097

    Post summary

    The post announces CVE-2026-40097 as an index out‑of‑bounds panic in Step CA’s TPM attestation handling, detailing its CVE‑2019‑40097 specifics and linking to a formal report.

    0000029
    36 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔵 Step CA, Index Out-of-Bounds Panic, #CVE-2026-40097 (Low) https://dailycve.com/step-ca-index-out-of-bounds-panic-cve-2026-40097-low/

    Post summary

    A low‑severity CVE-2026-40097 affecting Step CA’s index out‑of‑bounds handling is disclosed; no PoC, exploit, active use, patch, or debunking is mentioned.

    0000051
    181 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appsmallstepstep-ca-go-
Appsmallstepstep-ca0.30.0go-
Appsmallstepstep-ca0.30.0go-

Explore more