Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81868— Steeltoe: Header-forwarded client cert lacks proof of private-key possession

Quick assessment

Affected
SteeltoeOSS security-advisories
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Steeltoe 是一个开源项目,提供了一组帮助开发人员构建云原生应用程序的库。在 4.3.0 版本之前,使用 和 进行配置的 Steeltoe.Security.Authorization.Certificate 部署,会直接信任 请求头中提供的公钥证书,而不会验证请求者是否拥有相应的私钥。 常见的 Cloud Foundry 路由器不会从入站请求中移除该头部。当入站请求未限制来自已知的可信代理源 IP 时,攻击者若能获取目标组织或空间中某个应用程序实例的公钥证书,并且能够访问该应用程序,则可以在该证书有效期内通

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1083.004
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81868

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
Source: CVE Program / CVE List V5
Vulnerability Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the X-Client-Cert request header without proving possession of the corresponding private key. Common Cloud Foundry routers do not remove this header from inbound requests. When inbound requests are not restricted to a known trusted proxy source IP, an attacker who obtains the public certificate of an application instance in the target organization or space and can reach the application can spoof X-Client-Cert to bypass the SameOrg and SameSpace policies for the certificate validity period. This issue is fixed in version 4.3.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用候选路径或通道进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SteeltoeOSS security-advisories < 4.3.0 -

II. Public POCs for CVE-2026-81868

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81868

登录查看更多情报信息。

Vendor Advisories for CVE-2026-81868 (1)

Vendor Pages for CVE-2026-81868 (1)

Same Patch Batch · SteeltoeOSS · 2026-09-17 · 4 CVEs total

CVE-2026-81515 7.5 HIGH Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetc
CVE-2026-81516 7.5 HIGH Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS
CVE-2026-75523 5.9 MEDIUM Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets

IV. Related Vulnerabilities

V. Comments for CVE-2026-81868

No comments yet


Leave a comment