Steeltoe.Management.Endpoint
Steeltoe management endpoints, also known as actuators. Includes support for Cloud Foundry integration.
Activity
- Latest release
- 3mo ago
- Total releases
- 6
- Cadence
- ~5 months
- Last 12 months
- 2
Details
- License
- Apache-2.0
- First release
- Aug 30, 2017
| Version | Released | |
|---|---|---|
4.2.0
minor
|
4.2.0
minor
Dependencies (8)
|
|
4.1.0
minor
3 CVEs
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
4.1.0
minor
Dependencies (8)
|
|
4.0.0
initial
3 CVEs
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
4.0.0
initial
Dependencies (8)
|
|
4.0.0-rc1
pre
3 CVEs
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
4.0.0-rc1
pre
Dependencies (8)
|
|
4.0.0-beta1
pre
3 CVEs
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
4.0.0-beta1
pre
Dependencies (7)
|
|
1.1.0-rc3
pre
3 CVEs
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
1.1.0
1.1.0-rc3
4.0.0
4.0.0-beta1
4.0.0-rc1
4.1.0
Fixed in
4.2.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
1.1.0-rc3
pre
Dependencies (6)
|