Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-50202— Steeltoe's static JWKS cache shared across schemes and never invalidated

Quick assessment

Affected
SteeltoeOSS Steeltoe.Security.Authentication.CloudFoundryBase
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SteeltoeOSS Steeltoe.Security.Authentication.CloudFoundryBase是SteeltoeOSS的一个安全认证框架组件。 Steeltoe.Security.Authentication.CloudFoundryBase 3.4.0之前版本、Steeltoe.Security.Authentication.JwtBearer 4.2.0之前版本和Steeltoe.Security.Authentication.OpenIdConnect 4.2.0之前版本

CVSS 5.9 · Medium EPSS 0.29% · P22

Possible ATT&CK Techniques 1 AI

T1556 · Modify Authentication Process

Affected Version Matrix 3

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50202

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Steeltoe's static JWKS cache shared across schemes and never invalidated
Source: CVE Program / CVE List V5
Vulnerability Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect prior to version 4.2.0, the JWT signing key cache in `TokenKeyResolver` uses `kid` as the sole cache key without namespacing by authority. In applications with multiple `JwtBearer` schemes pointing to different identity providers, a key fetched for one scheme can satisfy token validation for another. Additionally, cached keys have no expiration, so rotated or revoked keys remain trusted until the application process restarts. Steeltoe.Security.Authentication.CloudFoundryBase version 3.4.0, Steeltoe.Security.Authentication.JwtBearer version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect version 4.2.0 patch the issue. If an immediate upgrade is not possible: In multi-scheme deployments, configure only one `JwtBearer` scheme per application when different identity providers are required; and/or restart the application process after an identity provider signing key rotation to clear stale cached keys.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
将资源暴露给错误范围
Source: CVE Program / CVE List V5
Vulnerability Title
SteeltoeOSS Steeltoe.Security.Authentication.CloudFoundryBase 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SteeltoeOSS Steeltoe.Security.Authentication.CloudFoundryBase是SteeltoeOSS的一个安全认证框架组件。 Steeltoe.Security.Authentication.CloudFoundryBase 3.4.0之前版本、Steeltoe.Security.Authentication.JwtBearer 4.2.0之前版本和Steeltoe.Security.Authentication.OpenIdConnect 4.2.0之前版本
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

II. Public POCs for CVE-2026-50202

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-50202

登录查看更多情报信息。

Patches & Fixes for CVE-2026-50202 (1)

Vendor Advisories for CVE-2026-50202 (1)

Same Patch Batch · SteeltoeOSS · 2026-06-17 · 7 CVEs total

CVE-2026-50194 8.2 HIGH Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-50196 7.5 HIGH Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVE-2026-50200 7.5 HIGH Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-50201 6.5 MEDIUM Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50267 4.7 MEDIUM Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVE-2026-50268 1.9 LOW Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

IV. Related Vulnerabilities

V. Comments for CVE-2026-50202

No comments yet


Leave a comment