Browse all 12 CVE security advisories affecting SteeltoeOSS. AI-powered Chinese analysis, POCs, and references for each vulnerability.
This page aggregates vulnerabilities associated with the vendor SteeltoeOSS, covering specific product weaknesses and security tags. The collection includes a broad spectrum of security flaws, ranging from memory corruption and input validation errors to authentication bypasses, documented over the recent several years of release cycles. Readers can use this hub to track the vendor's advisory history, understand the recurrence of specific weakness classes, and review the complete vulnerability timeline for SteeltoeOSS products. The aggregation provides a structured view of how individual issues map to broader vulnerability types, enabling security teams to assess risk trends and identify recurring patterns in the vendor's codebase. This resource supports detailed analysis for penetration testing, patch management, and compliance auditing by correlating historical data with current threat landscapes.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-50201 | Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission — Steeltoe.Management.Endpoint CWE-269 | 6.5 | Medium | 2026-06-17 |
| CVE-2026-50200 | Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords — Steeltoe.Management.Endpoint CWE-200 | 7.5 | High | 2026-06-17 |
| CVE-2026-50194 | Steeltoe vulnerable to management-port isolation bypass via spoofed Host header — Steeltoe.Management.Endpoint CWE-288 | 8.2 | High | 2026-06-17 |
This page lists every published CVE security advisory associated with SteeltoeOSS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.