Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-50268— Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

Quick assessment

Affected
SteeltoeOSS Steeltoe.Configuration.Encryption
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SteeltoeOSS Steeltoe.Configuration.Encryption是SteeltoeOSS的一个配置加密组件。 SteeltoeOSS Steeltoe.Configuration.Encryption 4.0.0版本至4.1.0版本存在信任管理问题漏洞,该漏洞源于BouncyCastle转换字符串不正确,导致OAEP设置选择了PKCS#1 v1.5算法,可能造成信任管理问题和加密问题。

CVSS 1.9 · Low EPSS 0.06% · P0

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 1

VendorProduct Version RangeStatus
SteeltoeOSS Steeltoe.Configuration.Encryption >= 4.0.0, < 4.2.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50268

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
Source: CVE Program / CVE List V5
Vulnerability Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the `OAEP` setting selects PKCS#1 v1.5, which is the same algorithm as the `DEFAULT` setting. Steeltoe.Configuration.Encryption version 4.2.0 patches the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
明文存储口令
Source: CVE Program / CVE List V5
Vulnerability Title
SteeltoeOSS Steeltoe.Configuration.Encryption 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SteeltoeOSS Steeltoe.Configuration.Encryption是SteeltoeOSS的一个配置加密组件。 SteeltoeOSS Steeltoe.Configuration.Encryption 4.0.0版本至4.1.0版本存在信任管理问题漏洞,该漏洞源于BouncyCastle转换字符串不正确,导致OAEP设置选择了PKCS#1 v1.5算法,可能造成信任管理问题和加密问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
SteeltoeOSS Steeltoe.Configuration.Encryption >= 4.0.0, < 4.2.0 -

II. Public POCs for CVE-2026-50268

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-50268

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-50268 (1)

Vendor Advisories for CVE-2026-50268 (1)

Same Patch Batch · SteeltoeOSS · 2026-06-17 · 7 CVEs total

CVE-2026-50194 8.2 HIGH Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-50196 7.5 HIGH Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVE-2026-50200 7.5 HIGH Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-50201 6.5 MEDIUM Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50202 5.9 MEDIUM Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-50267 4.7 MEDIUM Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

IV. Related Vulnerabilities

V. Comments for CVE-2026-50268

No comments yet


Leave a comment