Security Vulnerabilities in Smallstep PKI Software Copyright 2026 Andrew Ayer Andrew Ayer Dec 17, 2020 Smallstep's PKI software is vulnerable to JSON injection, misuses JWTs, and relies on client-side enforcement of server-side security. 0 inbound links en