CVE-2026-40097 | smallstep certificates up to 0.30.0-rc2 array index (GHSA-9qq8-cgcv-qmc9)
A vulnerability was found in smallstep certificates up to 0.30.0-rc2. It has been classified as problematic. This impacts an unknown function. This manipulation causes improper validation of array index.
This vulnerability appears as CVE-2026-40097. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.