Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81515— Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)

Quick assessment

Affected
SteeltoeOSS security-advisories
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Steeltoe 是一个开源项目,提供了一系列用于构建云原生应用程序的库。从版本 4.0.0 到 4.3.0, 将注册表响应作为单个单元进行反序列化。如果响应中包含无法识别的 或 、非布尔型的 ,或非数字型的 ,都可能导致整个响应被中止处理。 能够注册或更新实例的用户(principal)可以导致所有已连接的 Steeltoe 客户端接收到空实例列表或过时的实例列表,直到该格式错误的注册信息被移除为止。 受影响的解析路径包括 、 和 。此问题与此前发现的 解析漏洞不同。该问题已在版本 4.3.0 中修复。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81515

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
Source: CVE Program / CVE List V5
Vulnerability Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deserializes the registry response as one unit, and an unrecognized actionType or status, a non-Boolean isCoordinatingDiscoveryServer, or a nonnumeric timestamp can abort the entire response. A principal that can register or update an instance can cause all connected Steeltoe clients to receive an empty or stale instance list until the malformed registration is removed. The JsonInstanceInfoConverter, BoolStringJsonConverter, and LongStringJsonConverter parsing paths are affected. This issue is distinct from the earlier DataCenterInfo.name parsing vulnerability. This issue is fixed in version 4.3.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对异常条件的处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SteeltoeOSS security-advisories >= 4.0.0, < 4.3.0 -

II. Public POCs for CVE-2026-81515

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81515

登录查看更多情报信息。

Patches & Fixes for CVE-2026-81515 (1)

Vendor Advisories for CVE-2026-81515 (1)

Vendor Pages for CVE-2026-81515 (1)

Same Patch Batch · SteeltoeOSS · 2026-09-17 · 4 CVEs total

CVE-2026-81516 7.5 HIGH Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS
CVE-2026-81868 6.5 MEDIUM Steeltoe: Header-forwarded client cert lacks proof of private-key possession
CVE-2026-75523 5.9 MEDIUM Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets

IV. Related Vulnerabilities

V. Comments for CVE-2026-81515

No comments yet


Leave a comment