{"id":"CVE-2026-50200","title":"Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords","summary":"Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords","severity":"high","cvss":7.5,"cwe":["CWE-200","CWE-319"],"vendor":"Steeltoe","product":"Steeltoe.Management.Endpoint","ecosystem":"nuget","affected":["Steeltoe.Management.Endpoint <= 4.1.0","Steeltoe.Management.EndpointCore <= 3.3.0"],"patched":["Steeltoe.Management.Endpoint 4.2.0","Steeltoe.Management.EndpointCore 3.4.0"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q62h-354g-5r85","references":[{"url":"https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-q62h-354g-5r85"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50200"},{"url":"https://github.com/SteeltoeOSS/Steeltoe/commit/bef9f14b710232fca3fbe87e48fdd1b9e6b60d43"},{"url":"https://github.com/SteeltoeOSS/Steeltoe/commit/e50cd31a429b191841120f0d38fa9dda8f751b0a"},{"url":"https://github.com/advisories/GHSA-q62h-354g-5r85"}],"tags":["ghsa","nuget"],"epss":0.00185,"epssPercentile":0.08331,"ingestedAt":"2026-07-02T20:42:45.632Z","slug":"CVE-2026-50200","body":"## Overview\n\n### Summary\n\nThe `Sanitizer` component in the Environment actuator redacts configuration values by matching the configuration key name against a suffix list. The default list (`password`, `secret`, `key`, `token`, `.*credentials.*`, `vcap_services`) does not cover the standard .NET pattern `ConnectionStrings:<name>` or Steeltoe Connectors' `Steeltoe:Client:<type>:Default:ConnectionString`. There is no value-based scrubbing, so full connection string values including embedded `Password=` and `user:pass@host` segments are returned verbatim in `/actuator/env` responses.\n\n### Impact\n\nAny caller who can reach `/actuator/env` can receive connection strings containing plaintext credentials. Those credentials enable direct connection to the backing database, bypassing the application tier.\n\n### Affected configuration\n\n- Application configuration contains credentials in `ConnectionStrings:*` or `*:ConnectionString` keys.\n- On standard deployments: `env` is added to `Management:Endpoints:Actuator:Exposure:Include`. This is not the default.\n- On Cloud Foundry: the `/cloudfoundryapplication/env` path is accessible to any authenticated CF user with `read_basic_data` permissions (Space Auditor and above) regardless of the exposure configuration.\n\n### Mitigations\n\nIf an immediate upgrade is not possible:\n\n- On the standard path, remove `env` from the actuator exposure list.\n- Add `.*connectionstring.*` to `KeysToSanitize` as a defense-in-depth measure for both paths.\n- Require authorization on actuator endpoints.\n\n## Affected packages\n\n- `Steeltoe.Management.Endpoint <= 4.1.0`\n- `Steeltoe.Management.EndpointCore <= 3.3.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `Steeltoe.Management.Endpoint 4.2.0`\n- `Steeltoe.Management.EndpointCore 3.4.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}