Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Steeltoeoss
Steeltoeoss steeltoe.management.endpoint Steeltoeoss steeltoe.management.endpointcore |
|
| Vendors & Products |
Steeltoeoss
Steeltoeoss steeltoe.management.endpoint Steeltoeoss steeltoe.management.endpointcore |
Thu, 18 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is configured), the middleware responsible for restricting access to the endpoints uses the `Host` HTTP header rather than the actual network socket port. Versions 3.4.0 and 4.2.0 patch the issue. If an immediate upgrade to a patched version is not possible, add explicit ASP.NET Core authorization (`RequireAuthorization`) to all sensitive actuator endpoints as a defense-in-depth measure independent of port isolation and/or configure the reverse proxy or load balancer to enforce the `Host` header value and prevent clients from setting an arbitrary port. | |
| Title | Steeltoe vulnerable to management-port isolation bypass via spoofed Host header | |
| Weaknesses | CWE-288 CWE-639 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-18T19:12:49.831Z
Reserved: 2026-06-03T22:05:13.645Z
Link: CVE-2026-50194
Updated: 2026-06-18T19:12:38.893Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:57:00Z