Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-50194— Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

Quick assessment

Affected
SteeltoeOSS Steeltoe.Management.Endpoint
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SteeltoeOSS Steeltoe.Management.Endpoint是SteeltoeOSS的一个应用程序管理端点组件。 SteeltoeOSS Steeltoe.Management.Endpoint 4.2.0之前版本和Steeltoe.Management.EndpointCore 3.2.2版本至3.4.0之前版本存在授权问题漏洞,该漏洞源于中间件使用Host HTTP标头而非实际网络套接字端口来限制端点访问,可能导致未经身份验证的攻击者通过网络访问绕过访问控制,获取敏感信息。

CVSS 8.2 · High EPSS 0.41% · P34

Possible ATT&CK Techniques 2 AI

T1090 · Proxy T1078 · Valid Accounts

Affected Version Matrix 2

VendorProduct Version RangeStatus
SteeltoeOSS Steeltoe.Management.Endpoint < 4.2.0 affected
SteeltoeOSS Steeltoe.Management.EndpointCore >= 3.2.2, < 3.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50194

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Source: CVE Program / CVE List V5
Vulnerability Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is configured), the middleware responsible for restricting access to the endpoints uses the `Host` HTTP header rather than the actual network socket port. Versions 3.4.0 and 4.2.0 patch the issue. If an immediate upgrade to a patched version is not possible, add explicit ASP.NET Core authorization (`RequireAuthorization`) to all sensitive actuator endpoints as a defense-in-depth measure independent of port isolation and/or configure the reverse proxy or load balancer to enforce the `Host` header value and prevent clients from setting an arbitrary port.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用候选路径或通道进行的认证绕过
Source: CVE Program / CVE List V5
Vulnerability Title
SteeltoeOSS Steeltoe.Management.Endpoint 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SteeltoeOSS Steeltoe.Management.Endpoint是SteeltoeOSS的一个应用程序管理端点组件。 SteeltoeOSS Steeltoe.Management.Endpoint 4.2.0之前版本和Steeltoe.Management.EndpointCore 3.2.2版本至3.4.0之前版本存在授权问题漏洞,该漏洞源于中间件使用Host HTTP标头而非实际网络套接字端口来限制端点访问,可能导致未经身份验证的攻击者通过网络访问绕过访问控制,获取敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
SteeltoeOSS Steeltoe.Management.Endpoint < 4.2.0 -
SteeltoeOSS Steeltoe.Management.EndpointCore >= 3.2.2, < 3.4.0 -

II. Public POCs for CVE-2026-50194

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 8814 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-50194

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-50194 (2)

Vendor Advisories for CVE-2026-50194 (1)

Same Patch Batch · SteeltoeOSS · 2026-06-17 · 7 CVEs total

CVE-2026-50196 7.5 HIGH Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVE-2026-50200 7.5 HIGH Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-50201 6.5 MEDIUM Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50202 5.9 MEDIUM Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-50267 4.7 MEDIUM Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVE-2026-50268 1.9 LOW Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

IV. Related Vulnerabilities

V. Comments for CVE-2026-50194

No comments yet


Leave a comment