Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-50200— Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

Quick assessment

Affected
SteeltoeOSS Steeltoe.Management.Endpoint
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SteeltoeOSS Steeltoe.Management.Endpoint是SteeltoeOSS的一个应用程序管理端点组件。 SteeltoeOSS Steeltoe.Management.Endpoint 4.2.0之前版本和Steeltoe.Management.EndpointCore 3.4.0之前版本存在信息泄露漏洞,该漏洞源于Environment actuator中的Sanitizer组件配置清理不当,默认后缀列表未覆盖ConnectionStrings模式,可能导致完整连接字符串信

CVSS 7.5 · High EPSS 0.31% · P21

Affected Version Matrix 2

VendorProduct Version RangeStatus
SteeltoeOSS Steeltoe.Management.Endpoint < 4.2.0 affected
SteeltoeOSS Steeltoe.Management.EndpointCore < 3.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50200

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
Source: CVE Program / CVE List V5
Vulnerability Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` component in the Environment actuator redacts configuration values by matching the configuration key name against a suffix list. The default list (`password`, `secret`, `key`, `token`, `.*credentials.*`, `vcap_services`) does not cover the standard .NET pattern `ConnectionStrings:<name>` or Steeltoe Connectors' `Steeltoe:Client:<type>:Default:ConnectionString`. There is no value-based scrubbing, so full connection string values including embedded `Password=` and `user:pass@host` segments are returned verbatim in `/actuator/env` responses. Steeltoe.Management.Endpoint 4.2.0 and Steeltoe.Management.EndpointCore 3.4.0 patch the issue. If an immediate upgrade is not possible: On the standard path, remove `env` from the actuator exposure list; add `.*connectionstring.*` to `KeysToSanitize` as a defense-in-depth measure for both paths; and/or require authorization on actuator endpoints.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
SteeltoeOSS Steeltoe.Management.Endpoint 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SteeltoeOSS Steeltoe.Management.Endpoint是SteeltoeOSS的一个应用程序管理端点组件。 SteeltoeOSS Steeltoe.Management.Endpoint 4.2.0之前版本和Steeltoe.Management.EndpointCore 3.4.0之前版本存在信息泄露漏洞,该漏洞源于Environment actuator中的Sanitizer组件配置清理不当,默认后缀列表未覆盖ConnectionStrings模式,可能导致完整连接字符串信
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
SteeltoeOSS Steeltoe.Management.Endpoint < 4.2.0 -
SteeltoeOSS Steeltoe.Management.EndpointCore < 3.4.0 -

II. Public POCs for CVE-2026-50200

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 9773 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-50200

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-50200 (2)

Vendor Advisories for CVE-2026-50200 (1)

Same Patch Batch · SteeltoeOSS · 2026-06-17 · 7 CVEs total

CVE-2026-50194 8.2 HIGH Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-50196 7.5 HIGH Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVE-2026-50201 6.5 MEDIUM Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50202 5.9 MEDIUM Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-50267 4.7 MEDIUM Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVE-2026-50268 1.9 LOW Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

IV. Related Vulnerabilities

V. Comments for CVE-2026-50200

No comments yet


Leave a comment