Steeltoe.Discovery.Eureka
Client for service discovery and registration with Netflix Eureka.
Activity
- Latest release
- 5d ago
- Total releases
- 28
- Cadence
- ~2 months
- Last 12 months
- 4
Details
- License
- Apache-2.0
- First release
- Aug 07, 2020
| Version | Released | |
|---|---|---|
4.3.0
minor
|
4.3.0
minor
Dependencies (3)
|
|
3.4.0
minor
|
3.4.0
minor
Dependencies (4)
|
|
4.2.0
minor
|
4.2.0
minor
Dependencies (3)
|
|
4.1.0
minor
1 CVE
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
4.1.0
minor
Dependencies (3)
|
|
4.0.0
major
1 CVE
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
4.0.0
major
Dependencies (3)
|
|
3.3.0
minor
1 CVE
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (4)
|
|
4.0.0-rc1
pre
|
4.0.0-rc1
pre
Dependencies (3)
|
|
4.0.0-beta1
pre
|
4.0.0-beta1
pre
Dependencies (3)
|
|
3.2.8
patch
1 CVE
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.8
patch
Dependencies (4)
|
|
3.2.7
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.7
patch
Dependencies (4)
|
|
3.2.6
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.6
patch
Dependencies (4)
|
|
3.2.5
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.5
patch
Dependencies (4)
|
|
3.2.4
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.4
patch
Dependencies (4)
|
|
3.2.3
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.3
patch
Dependencies (4)
|
|
3.2.2
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.2
patch
Dependencies (4)
|
|
3.2.1
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.1
patch
Dependencies (4)
|
|
3.2.0
minor
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (4)
|
|
3.2.0-rc1
pre
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.0-rc1
pre
Dependencies (4)
|
|
3.1.3
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.3
patch
Dependencies (4)
|
|
3.1.2
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (4)
|
|
3.1.1
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (4)
|
|
3.1.0
minor
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (4)
|
|
3.1.0-rc2
pre
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0-rc2
pre
Dependencies (4)
|
|
3.1.0-rc1
pre
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0-rc1
pre
Dependencies (4)
|
|
3.0.2
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (4)
|
|
3.0.1
patch
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (4)
|
|
3.0.0
initial
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0
initial
Dependencies (4)
|
|
3.0.0-rc1
pre
2 CVEs
CVE-2026-50196
GHSA-j8ph-6fxj-g533
Jul 02, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
ImpactAny registration with an unrecognized Because Affected configuration
MitigationsIf an immediate upgrade is not possible, remove any registrations using unsupported Affected versions
4.0.0
4.1.0
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
+ 11 more Show less
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2024-40636
GHSA-vmcp-66r5-3pcp
Jul 17, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
Local
Low
Low
None
SummaryWhen utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. DetailsPackage: Steeltoe.Discovery.Eureka
Package version: 3.2.1
Branch: "release/3.2"
File name: Error message in logs: I thought PoC
ImpactVulnerability: Credential leakage in the logs Who does it impact?: Users who are using peer awareness with Spring Eureka Affected versions
3.0.0
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
+ 7 more Show less
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
Fixed in
3.2.8
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-rc1
pre
Dependencies (4)
|