Skip to content

vulnerability in zrok project #1120

@ankitdn

Description

@ankitdn

While working on zrok project, I identified a vulnerability (CVE-2025-66406) in Step CA’s SSHPOP provisioner. Due to an improper authorization check, an attacker with limited access could revoke SSH certificates without proper permissions, potentially disrupting secure access across systems using these certificates.

CVE Link
CVE Report

Metadata

Metadata

Labels

dependenciesPull requests that update a dependency file

Type

No type

Projects

Status

Done

Relationships

None yet

Development

No branches or pull requests

Issue actions