Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SteeltoeOSS — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting SteeltoeOSS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerabilities associated with the vendor SteeltoeOSS, covering specific product weaknesses and security tags. The collection includes a broad spectrum of security flaws, ranging from memory corruption and input validation errors to authentication bypasses, documented over the recent several years of release cycles. Readers can use this hub to track the vendor's advisory history, understand the recurrence of specific weakness classes, and review the complete vulnerability timeline for SteeltoeOSS products. The aggregation provides a structured view of how individual issues map to broader vulnerability types, enabling security teams to assess risk trends and identify recurring patterns in the vendor's codebase. This resource supports detailed analysis for penetration testing, patch management, and compliance auditing by correlating historical data with current threat landscapes.

CVE ID Title CVSS Severity Published
CVE-2026-81515 Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS) — security-advisories CWE-755 7.5 High 2026-09-17
CVE-2026-81516 Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS) — security-advisories CWE-755 7.5 High 2026-09-17
CVE-2026-81868 Steeltoe: Header-forwarded client cert lacks proof of private-key possession — security-advisories CWE-288 6.5 Medium 2026-09-17
CVE-2026-75523 Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets — security-advisories CWE-200 5.9 Medium 2026-09-17
CVE-2026-50268 Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding — Steeltoe.Configuration.Encryption CWE-256 1.9 Low 2026-06-17
CVE-2026-50267 Steeltoe: TLS private keys written to /tmp with default permissions, never deleted — Steeltoe.Configuration.Abstractions CWE-312 4.7 Medium 2026-06-17
CVE-2026-50202 Steeltoe's static JWKS cache shared across schemes and never invalidated — Steeltoe.Security.Authentication.CloudFoundryBase CWE-668 5.9 Medium 2026-06-17
CVE-2026-50201 Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission — Steeltoe.Management.Endpoint CWE-269 6.5 Medium 2026-06-17
CVE-2026-50200 Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords — Steeltoe.Management.Endpoint CWE-200 7.5 High 2026-06-17
CVE-2026-50196 Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch — Steeltoe.Discovery.Eureka CWE-20 7.5 High 2026-06-17
CVE-2026-50194 Steeltoe vulnerable to management-port isolation bypass via spoofed Host header — Steeltoe.Management.Endpoint CWE-288 8.2 High 2026-06-17
CVE-2024-40636 Basic Auth Credential Leakage to Logs After Fetch Registry Error in Steeltoe.Discovery.Eureka with Peer Awareness — security-advisories CWE-532 5.3 Medium 2024-07-17

This page lists every published CVE security advisory associated with SteeltoeOSS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.