---
id: CVE-2026-50200
title: >-
  Steeltoe's env sanitizer misses connection strings — leaks embedded DB
  passwords
summary: >-
  Steeltoe's env sanitizer misses connection strings — leaks embedded DB
  passwords
severity: high
cvss: 7.5
cwe:
  - CWE-200
  - CWE-319
vendor: Steeltoe
product: Steeltoe.Management.Endpoint
ecosystem: nuget
affected:
  - Steeltoe.Management.Endpoint <= 4.1.0
  - Steeltoe.Management.EndpointCore <= 3.3.0
patched:
  - Steeltoe.Management.Endpoint 4.2.0
  - Steeltoe.Management.EndpointCore 3.4.0
published: '2026-07-02'
updated: '2026-07-02'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-q62h-354g-5r85'
references:
  - url: >-
      https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-q62h-354g-5r85
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50200'
  - url: >-
      https://github.com/SteeltoeOSS/Steeltoe/commit/bef9f14b710232fca3fbe87e48fdd1b9e6b60d43
  - url: >-
      https://github.com/SteeltoeOSS/Steeltoe/commit/e50cd31a429b191841120f0d38fa9dda8f751b0a
  - url: 'https://github.com/advisories/GHSA-q62h-354g-5r85'
tags:
  - ghsa
  - nuget
epss: 0.00306
epssPercentile: 0.20742
ingestedAt: '2026-07-02T20:42:45.632Z'
---

## Overview

### Summary

The `Sanitizer` component in the Environment actuator redacts configuration values by matching the configuration key name against a suffix list. The default list (`password`, `secret`, `key`, `token`, `.*credentials.*`, `vcap_services`) does not cover the standard .NET pattern `ConnectionStrings:<name>` or Steeltoe Connectors' `Steeltoe:Client:<type>:Default:ConnectionString`. There is no value-based scrubbing, so full connection string values including embedded `Password=` and `user:pass@host` segments are returned verbatim in `/actuator/env` responses.

### Impact

Any caller who can reach `/actuator/env` can receive connection strings containing plaintext credentials. Those credentials enable direct connection to the backing database, bypassing the application tier.

### Affected configuration

- Application configuration contains credentials in `ConnectionStrings:*` or `*:ConnectionString` keys.
- On standard deployments: `env` is added to `Management:Endpoints:Actuator:Exposure:Include`. This is not the default.
- On Cloud Foundry: the `/cloudfoundryapplication/env` path is accessible to any authenticated CF user with `read_basic_data` permissions (Space Auditor and above) regardless of the exposure configuration.

### Mitigations

If an immediate upgrade is not possible:

- On the standard path, remove `env` from the actuator exposure list.
- Add `.*connectionstring.*` to `KeysToSanitize` as a defense-in-depth measure for both paths.
- Require authorization on actuator endpoints.

## Affected packages

- `Steeltoe.Management.Endpoint <= 4.1.0`
- `Steeltoe.Management.EndpointCore <= 3.3.0`

## Remediation

Upgrade to a patched release:

- `Steeltoe.Management.Endpoint 4.2.0`
- `Steeltoe.Management.EndpointCore 3.4.0`
