Steeltoe has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 7. The median CVSS is 6.2 (medium). None have a confirmed exploitation report. Most affected products: Steeltoe.Management.Endpoint (4), Steeltoe.Configuration.Abstractions (1), Steeltoe.Configuration.Encryption (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.2
- Publish → KEV
- —
- Last 90 days
- 8 prev 0
Products
- Steeltoe.Management.Endpoint 4
- Steeltoe.Configuration.Abstractions 1
- Steeltoe.Configuration.Encryption 1
- Steeltoe.Discovery.Eureka 1
- Steeltoe.Security.Authentication.JwtBearer 1
Worst active — by depth score
CVE-2026-50194High· 8.2Steeltoe vulnerable to management-port isolation bypass via spoofed Host header45CVE-2026-50200High· 7.5Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords41CVE-2026-50196High· 7.5Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch41CVE-2026-50201Medium· 6.5Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission36CVE-2026-75523Medium· 5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications33
Steeltoe vulnerabilities
CVEs affecting Steeltoe, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-75523Medium· 5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs t…
CVE-2026-50194High· 8.2Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-50196High· 7.5Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVE-2026-50200High· 7.5Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-50201Medium· 6.5Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50202Medium· 5.9Steeltoe's static JWKS cache shared across schemes and never invalidated
Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-50267Medium· 4.7Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVE-2026-50268Low· 1.9Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding