Steeltoe.Management.EndpointCore vulnerabilities
CVEs whose affected-version data names the Steeltoe.Management.EndpointCore package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-50194High· 8.2Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.24%via GHSA
CVE-2026-50200High· 7.5Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.18%via GHSA