Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 17+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Clear filters
Medium
Security Fix: Improper Temp File Permissions in MySQL/PostgreSQL Connectors
github.com · 2026-06-18
Steeltoe MySQL/PostgreSQL Connectors
Read more
High
Steeltoe OSS ConfigServer RSA Encryption Algorithm Downgrade Fix
github.com · 2026-06-18
Steeltoe ConfigServer · Steeltoe Test
Read more
Unknown
CVE-2025-5208 RSA OAEP silently falls back to PKCS#1 v1.5 padding
CVE-2025-5208 · github.com · 2026-06-18
Steeltoe >= 4.0.0, <= 4.1.0
Read more
Medium
Steeltoe TLS Private Key Disclosure via Insecure /tmp Permissions (CVE-2025-2627)
CVE-2025-2627 · github.com · 2026-06-18
Steeltoe.Configuration.Abstractions (Net) >= 4.0.0, <= 4.1.0
Read more
High
Fix for Unauthorized Access to Spring Boot Actuator /env, /dump, /heapdump Endpoints
github.com · 2026-06-18

### Vulnerability Overview This vulnerability involves an issue requiring full permissions (`FULL Permissions`) for the `/env`, `/dump`, and `/heapdump` endpoints. ### Impact Scope - **Affected Files*…

Read more
Premium intel
High
Steeltoe JWT Key Cache Not Isolated Across Schemes: CVE-2025-50202
CVE-2025-50202 · github.com · 2026-06-18
Steeltoe.Security.Authentication.CloudFoundryBase <= 3.3.0 · Steeltoe.Security.Authentication.JwtBearer <= 4.1.0 …
Read more
Medium
Spring Boot Actuator Endpoint Permissions Bypass Leads to Sensitive Data Disclosure (CVE-2026-00201)
CVE-2026-00201 · github.com · 2026-06-18
Steeltoe.Management.Endpoint <= 4.1.0 · Steeltoe.Management.EndpointBase <= 3.3.0
Read more
High
Steeltoe Management Port Isolation Bypass via Host Header Spoofing (CVE-2026-5034)
CVE-2026-5034 · github.com · 2026-06-18
Steeltoe.Management.Endpoint <= 4.1.0 · Steeltoe.Management.EndpointCore >= 3.2.2, <= 3.3.0
Read more
Premium intel
Medium
Eureka DataCenterName Validation Bypass Vulnerability
github.com · 2026-06-18
Steeltoe 3.4.0
Read more
Premium intel
Unknown
Spring Cloud Eureka DataCenterInfo Deserialization Exception Fix
github.com · 2026-06-18
Steeltoe Discovery Eureka
Read more
Critical
CVE-2024-50200: Steeltoe Env Actuator Leaks Database Plaintext Passwords
CVE-2024-50200 · github.com · 2026-06-18
Steeltoe.Management.Endpoint <= 4.1.0 · Steeltoe.Management.EndpointCore <= 3.3.0
Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.