Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75523— Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets

Quick assessment

Affected
SteeltoeOSS security-advisories
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Steeltoe 是一个开源项目,提供了一系列用于构建云原生应用的库。在 4.3.0 版本之前,Steeltoe 的 端点会通过 处理记录的请求 URI,该机制仅对 URI 中的用户信息进行掩码,但未检查查询字符串。当启用 配置时, 的响应可能会向任何能够访问该显式暴露端点的调用者泄露之前请求中的查询字符串敏感信息,例如 OAuth 令牌、密码重置令牌、签名 URL 的签名、API 密钥等。此外, 的 DEBUG 级别日志记录器也会记录这些 URI,从而为拥有日志访问权限的用户创建了第二条信息泄露途径。该问题已在

CVSS 5.9 · Medium

Possible ATT&CK Techniques 1 AI

T1213 · Data from Information Repositories
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75523

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
Source: CVE Program / CVE List V5
Vulnerability Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query strings. When Management:Endpoints:HttpExchanges:IncludeQueryString is enabled, the HttpExchangeRequest response can disclose OAuth tokens, password-reset tokens, signed-URL signatures, API keys, and other query-string secrets from prior traffic to a caller that can reach the explicitly exposed endpoint. The Steeltoe.Management.Endpoint.Actuators.HttpExchanges DEBUG logger also records these URIs, creating a second disclosure channel for users with log access. This issue is fixed in version 4.3.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SteeltoeOSS security-advisories < 4.3.0 -

II. Public POCs for CVE-2026-75523

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75523

登录查看更多情报信息。

Patches & Fixes for CVE-2026-75523 (1)

Vendor Advisories for CVE-2026-75523 (1)

Vendor Pages for CVE-2026-75523 (1)

Same Patch Batch · SteeltoeOSS · 2026-09-17 · 4 CVEs total

CVE-2026-81515 7.5 HIGH Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetc
CVE-2026-81516 7.5 HIGH Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS
CVE-2026-81868 6.5 MEDIUM Steeltoe: Header-forwarded client cert lacks proof of private-key possession

IV. Related Vulnerabilities

V. Comments for CVE-2026-75523

No comments yet


Leave a comment