Steeltoe.Management.Endpoint vulnerabilities
CVEs whose affected-version data names the Steeltoe.Management.Endpoint package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-75523Medium· 5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs t…
▾ SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.29%via NVD
CVE-2026-50194High· 8.2Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.24%via GHSA
CVE-2026-50200High· 7.5Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.18%via GHSA
CVE-2026-50201Medium· 6.5Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
▾ SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.23%via GHSA