Steeltoe.Management.EndpointBase
Steeltoe management endpoints.
Activity
- Latest release
- 3mo ago
- Total releases
- 48
- Cadence
- ~2 months
- Last 12 months
- 1
Details
- License
- Apache-2.0
- First release
- Dec 19, 2017
| Version | Released | |
|---|---|---|
3.4.0
minor
|
3.4.0
minor
Dependencies (17)
+ 9 more |
|
4.0.0
major
|
4.0.0
major
|
|
3.3.0
minor
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (17)
+ 9 more |
|
3.2.8
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.8
patch
Dependencies (15)
+ 7 more |
|
3.2.7
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.7
patch
Dependencies (15)
+ 7 more |
|
3.2.6
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.6
patch
Dependencies (15)
+ 7 more |
|
3.2.5
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.5
patch
Dependencies (15)
+ 7 more |
|
3.2.4
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.4
patch
Dependencies (15)
+ 7 more |
|
3.2.3
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.3
patch
Dependencies (15)
+ 7 more |
|
3.2.2
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.2
patch
Dependencies (15)
+ 7 more |
|
3.2.1
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.1
patch
Dependencies (15)
+ 7 more |
|
3.2.0
minor
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (15)
+ 7 more |
|
3.2.0-rc1
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.0-rc1
pre
Dependencies (15)
+ 7 more |
|
3.1.3
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.3
patch
Dependencies (15)
+ 7 more |
|
3.1.2
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (15)
+ 7 more |
|
2.5.5
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.5
patch
Dependencies (12)
+ 4 more |
|
3.1.1
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (15)
+ 7 more |
|
3.1.0
minor
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (15)
+ 7 more |
|
3.1.0-rc2
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.0-rc2
pre
Dependencies (14)
+ 6 more |
|
2.5.4
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.4
patch
Dependencies (12)
+ 4 more |
|
3.1.0-rc1
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.0-rc1
pre
Dependencies (14)
+ 6 more |
|
2.5.3
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.3
patch
Dependencies (12)
+ 4 more |
|
3.0.2
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (13)
+ 5 more |
|
2.5.2
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (12)
+ 4 more |
|
3.0.1
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (13)
+ 5 more |
|
2.5.1
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (12)
+ 4 more |
|
2.5.0
minor
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (12)
+ 4 more |
|
3.0.0
major
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (13)
+ 5 more |
|
3.0.0-rc1
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.0-rc1
pre
Dependencies (13)
+ 5 more |
|
2.4.4
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.4
patch
Dependencies (12)
+ 4 more |
|
2.4.3
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.3
patch
Dependencies (12)
+ 4 more |
|
2.4.2
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.2
patch
Dependencies (12)
+ 4 more |
|
2.4.1
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.1
patch
Dependencies (12)
+ 4 more |
|
2.4.0
minor
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (12)
+ 4 more |
|
2.4.0-rc1
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.0-rc1
pre
Dependencies (12)
+ 4 more |
|
2.2.1
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.1
patch
Dependencies (12)
+ 4 more |
|
2.3.0
minor
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (12)
+ 4 more |
|
2.3.0-rc2
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.3.0-rc2
pre
Dependencies (12)
+ 4 more |
|
2.3.0-rc1
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.3.0-rc1
pre
Dependencies (12)
+ 4 more |
|
2.2.0
minor
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (12)
+ 4 more |
|
2.2.0-rc2
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.0-rc2
pre
Dependencies (12)
+ 4 more |
|
2.2.0-rc1
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.0-rc1
pre
Dependencies (11)
+ 3 more |
|
2.1.1
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.1.1
patch
Dependencies (11)
+ 3 more |
|
2.1.0
minor
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (11)
+ 3 more |
|
2.1.0-rc1
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.1.0-rc1
pre
Dependencies (13)
+ 5 more |
|
2.0.1
patch
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.0.1
patch
Dependencies (8)
|
|
2.0.0
initial
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.0.0
initial
Dependencies (8)
|
|
2.0.0-rc1
pre
1 CVE
CVE-2026-50201
GHSA-227r-jm2g-7cp4
Jul 02, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
SummaryAll Steeltoe actuator endpoints default to ImpactAny CF user holding Space Auditor, Space Manager, or Org Auditor role can access the heap dump, environment, and thread dump actuators for any Steeltoe application in their space. A heap dump contains all in-memory data including database passwords, bearer tokens, and VCAP_SERVICES credentials. CF's Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 36 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.0.0-rc1
pre
Dependencies (5)
|