Known Vulnerabilities for Certificates by Smallstep
Listed below are 10 of the newest known vulnerabilities associated with "Certificates" by "Smallstep".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42225 json | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the S... | Not Provided | 2026-05-07 | 2026-05-07 |
| CVE-2026-42011 json | A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previo... | Not Provided | 2026-05-07 | 2026-05-07 |
| CVE-2026-40944 json | Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration on... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40865 json | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in t... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40557 json | Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: fro... | Not Provided | 2026-04-27 | 2026-04-30 |
| CVE-2026-40243 json | Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN dat... | Not Provided | 2026-05-06 | 2026-05-07 |
| CVE-2026-40070 json | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificat... | Not Provided | 2026-04-09 | 2026-04-13 |
| CVE-2026-39388 json | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authenticat... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-34582 json | Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to b... | Not Provided | 2026-04-07 | 2026-04-08 |
| CVE-2026-34580 json | Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it w... | Not Provided | 2026-04-07 | 2026-04-09 |