Known Vulnerabilities for Certificates by Smallstep
Listed below are 10 of the newest known vulnerabilities associated with "Certificates" by "Smallstep".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40070 json | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificat... | Not Provided | 2026-04-09 | 2026-04-09 |
| CVE-2026-34582 json | Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to b... | Not Provided | 2026-04-07 | 2026-04-08 |
| CVE-2026-34580 json | Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it w... | Not Provided | 2026-04-07 | 2026-04-08 |
| CVE-2026-34179 json | In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Typ... | Not Provided | 2026-04-09 | 2026-04-09 |
| CVE-2026-34073 json | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-33896 json | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0... | Not Provided | 2026-03-27 | 2026-03-30 |
| CVE-2026-33753 json | rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Autho... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-33697 json | Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulnerable ... | Not Provided | 2026-03-27 | 2026-03-27 |
| CVE-2026-33141 json | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in... | Not Provided | 2026-04-10 | 2026-04-10 |
| CVE-2026-32794 json | Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certi... | Not Provided | 2026-03-30 | 2026-03-31 |