Threat Advisory

Steeltoe Vulnerabilities Bypass Cloud Foundry Controls and Enable Session Spoofing

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Steeltoe.Management.Endpoint, Steeltoe.Discovery.Eureka, Steeltoe.Discovery.Consul, and Steeltoe.Security.Authorization.Certificate which could allow an attacker to leak query-string secrets cause service-discovery outages and bypass certain authorization policies respectively.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Steeltoe.Management.Endpoint, Steeltoe.Discovery.Eureka, Steeltoe.Discovery.Consul, and Steeltoe.Security.Authorization.Certificate which could allow an attacker to leak query-string secrets cause service-discovery outages and bypass certain authorization policies respectively.[emaillocker id="1283"]

CVE-2026-75523 (CVSS 5.9 — Medium): Steeltoe's endpoint records and displays request URIs after passing them through MaskedUri which does not inspect the query string allowing an attacker to receive full request URIs from prior traffic including any secrets those URIs contained in their query strings.

CVE-2026-81515 (CVSS 7.5 — High): Steeltoe Eureka fails to deserialize malformed isCoordinatingDiscoveryServer values causing empty or stale service-instance lists and service-discovery outages for connected applications.

CVE-2026-81516 (CVSS 7.5 — High): Steeltoe Consul fails to parse malformed secure metadata values causing GetAllInstancesAsync enumeration failures and service-discovery outages for connected applications.

CVE-2026-81868 (CVSS 6.5 — Medium): Steeltoe certificate authorization allows X-Client-Cert header spoofing enabling bypass of SameOrg and SameSpace authorization policies.

 

RECOMMENDATIONS:

  • We recommend you to update Steeltoe.Management.Endpoint, Steeltoe.Discovery.Eureka, Steeltoe.Discovery.Consul and Steeltoe.Security.Authorization.Certificate to version 4.3.0 or later.

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-8phw-xrj9-cpqp
https://github.com/advisories/GHSA-hr73-3gpv-hh6q
https://github.com/advisories/GHSA-67c9-f6v2-qv86
https://github.com/advisories/GHSA-5mq7-rwhj-4fh9

[/emaillocker]
crossmenu