VulnSea

Steeltoe has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 7. The median CVSS is 6.2 (medium). None have a confirmed exploitation report. Most affected products: Steeltoe.Management.Endpoint (4), Steeltoe.Configuration.Abstractions (1), Steeltoe.Configuration.Encryption (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.2
Publish → KEV
Last 90 days
8 prev 0

Products

  • Steeltoe.Management.Endpoint 4
  • Steeltoe.Configuration.Abstractions 1
  • Steeltoe.Configuration.Encryption 1
  • Steeltoe.Discovery.Eureka 1
  • Steeltoe.Security.Authentication.JwtBearer 1
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Steeltoe vulnerabilities

CVEs affecting Steeltoe, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-75523Medium· 5.9
5d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs t…

SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.29%via NVD
CVE-2026-50194High· 8.2
2mo ago

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.24%via GHSA
CVE-2026-50196High· 7.5
2mo ago

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

TwilightSteeltoe · Steeltoe.Discovery.EurekaEPSS 0.34%via GHSA
CVE-2026-50200High· 7.5
2mo ago

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.18%via GHSA
CVE-2026-50201Medium· 6.5
2mo ago

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.23%via GHSA
CVE-2026-50202Medium· 5.9
2mo ago

Steeltoe's static JWKS cache shared across schemes and never invalidated

Steeltoe's static JWKS cache shared across schemes and never invalidated

SunlitSteeltoe · Steeltoe.Security.Authentication.JwtBearerEPSS 0.29%via GHSA
CVE-2026-50267Medium· 4.7
2mo ago

Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

SunlitSteeltoe · Steeltoe.Configuration.AbstractionsEPSS 0.07%via GHSA
CVE-2026-50268Low· 1.9
2mo ago

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

SunlitSteeltoe · Steeltoe.Configuration.EncryptionEPSS 0.05%via GHSA
Steeltoe vulnerabilities (CVEs) · VulnSea