Steeltoe.Management.EndpointCore
Package for using Steeltoe management endpoints with ASP.NET Core.
Activity
- Latest release
- 3mo ago
- Total releases
- 48
- Cadence
- ~2 months
- Last 12 months
- 1
Details
- License
- Apache-2.0
- First release
- Dec 19, 2017
| Version | Released | |
|---|---|---|
3.4.0
minor
|
3.4.0
minor
Dependencies (8)
|
|
4.0.0
major
|
4.0.0
major
|
|
3.3.0
minor
2 CVEs
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (8)
|
|
3.2.8
patch
2 CVEs
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.8
patch
Dependencies (8)
|
|
3.2.7
patch
2 CVEs
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.7
patch
Dependencies (8)
|
|
3.2.6
patch
2 CVEs
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.6
patch
Dependencies (8)
|
|
3.2.5
patch
2 CVEs
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.5
patch
Dependencies (8)
|
|
3.2.4
patch
2 CVEs
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.4
patch
Dependencies (8)
|
|
3.2.3
patch
2 CVEs
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.3
patch
Dependencies (8)
|
|
3.2.2
patch
2 CVEs
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-50194
GHSA-58f6-6rj2-3v8r
Jul 02, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
8.2
/ 10
High
Network
Low
None
None
Unchanged
High
Low
None
SummaryWhen Steeltoe management endpoints are configured to listen on an alternate port ( ImpactAn unauthenticated remote attacker can reach every actuator endpoint using a specially crafted HTTP request. Affected configuration
MitigationsIf an immediate upgrade to a patched version is not possible:
Affected versions
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.2
patch
Dependencies (8)
|
|
3.2.1
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.1
patch
Dependencies (7)
|
|
3.2.0
minor
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (7)
|
|
3.2.0-rc1
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.0-rc1
pre
Dependencies (7)
|
|
3.1.3
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.3
patch
Dependencies (7)
|
|
3.1.2
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (7)
|
|
2.5.5
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.5
patch
Dependencies (9)
+ 1 more |
|
3.1.1
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (7)
|
|
3.1.0
minor
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (7)
|
|
3.1.0-rc2
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.0-rc2
pre
Dependencies (9)
+ 1 more |
|
2.5.4
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.4
patch
Dependencies (9)
+ 1 more |
|
3.1.0-rc1
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.0-rc1
pre
Dependencies (9)
+ 1 more |
|
2.5.3
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.3
patch
Dependencies (9)
+ 1 more |
|
3.0.2
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (9)
+ 1 more |
|
2.5.2
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (9)
+ 1 more |
|
3.0.1
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (9)
+ 1 more |
|
2.5.1
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (9)
+ 1 more |
|
2.5.0
minor
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (9)
+ 1 more |
|
3.0.0
major
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (9)
+ 1 more |
|
3.0.0-rc1
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.0-rc1
pre
Dependencies (9)
+ 1 more |
|
2.4.4
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.4
patch
Dependencies (9)
+ 1 more |
|
2.4.3
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.3
patch
Dependencies (9)
+ 1 more |
|
2.4.2
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.2
patch
Dependencies (9)
+ 1 more |
|
2.4.1
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.1
patch
Dependencies (9)
+ 1 more |
|
2.4.0
minor
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (9)
+ 1 more |
|
2.4.0-rc1
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.0-rc1
pre
Dependencies (9)
+ 1 more |
|
2.2.1
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.1
patch
Dependencies (8)
|
|
2.3.0
minor
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (10)
+ 2 more |
|
2.3.0-rc2
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.3.0-rc2
pre
Dependencies (10)
+ 2 more |
|
2.3.0-rc1
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.3.0-rc1
pre
Dependencies (10)
+ 2 more |
|
2.2.0
minor
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (8)
|
|
2.2.0-rc2
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.0-rc2
pre
Dependencies (8)
|
|
2.2.0-rc1
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.0-rc1
pre
Dependencies (8)
|
|
2.1.1
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.1.1
patch
Dependencies (7)
|
|
2.1.0
minor
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (7)
|
|
2.1.0-rc1
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.1.0-rc1
pre
Dependencies (8)
|
|
2.0.1
patch
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.0.1
patch
Dependencies (4)
|
|
2.0.0
initial
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.0.0
initial
Dependencies (4)
|
|
2.0.0-rc1
pre
1 CVE
CVE-2026-50200
GHSA-q62h-354g-5r85
Jul 02, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SummaryThe ImpactAny caller who can reach Affected configuration
MitigationsIf an immediate upgrade is not possible:
Affected versions
2.0.0
2.0.0-rc1
2.0.1
2.1.0
2.1.0-rc1
2.1.1
2.2.0
2.2.0-rc1
2.2.0-rc2
2.2.1
2.3.0
2.3.0-rc1
+ 37 more Show less
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.0.0-rc1
pre
Dependencies (4)
|