If you think you have found a security vulnerability, please DO NOT disclose it publicly until we've had a chance to fix it. Please don’t report security vulnerabilities using GitHub issues, instead head over to Steeltoe Security Policy and learn how to disclose them responsibly.
Security: SteeltoeOSS/security-advisories
Security
SECURITY.md
-
Unauthenticated RCE via argument injection into 'dotnet new' in NetCoreToolService (GET /api/new/{template}); bypasses EnableSensitiveEndpoints and runs template post-actionsGHSA-f5m5-jfmq-ghpx published
Jul 15, 2026 by TimHessCritical -
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secretsGHSA-8phw-xrj9-cpqp published
Sep 9, 2026 by TimHessModerate -
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)GHSA-67c9-f6v2-qv86 published
Sep 9, 2026 by TimHessHigh -
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)GHSA-hr73-3gpv-hh6q published
Sep 9, 2026 by TimHessHigh -
OAEP setting silently selects PKCS#1 v1.5 paddingGHSA-4j9m-h44m-2hv8 published
May 29, 2026 by TimHessLow -
TLS private keys written to /tmp with default permissions, never deletedGHSA-rxrh-4j9h-xgg9 published
May 29, 2026 by TimHessModerate -
Static JWKS cache shared across schemes and never invalidatedGHSA-7fqc-p256-7pwj published
May 29, 2026 by TimHessModerate -
Header-forwarded client cert lacks proof of private-key possessionGHSA-5mq7-rwhj-4fh9 published
Sep 9, 2026 by TimHessModerate -
Sensitive actuators (heapdump/env) only require Restricted permissionGHSA-227r-jm2g-7cp4 published
May 29, 2026 by TimHessModerate -
Env sanitizer misses connection strings — leaks embedded DB passwordsGHSA-q62h-354g-5r85 published
May 29, 2026 by TimHessHigh
Learn more about advisories related to SteeltoeOSS/security-advisories in the GitHub Advisory Database