Steeltoe.Security.Authentication.CloudFoundryBase
Base Security Provider for CloudFoundry.
Activity
- Latest release
- 3mo ago
- Total releases
- 32
- Cadence
- ~2 months
- Last 12 months
- 1
Details
- License
- Apache-2.0
- First release
- Mar 15, 2019
| Version | Released | |
|---|---|---|
3.4.0
minor
|
3.4.0
minor
Dependencies (8)
|
|
4.0.0
major
|
4.0.0
major
|
|
3.3.0
minor
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (7)
|
|
3.2.8
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.8
patch
Dependencies (3)
|
|
3.2.7
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.7
patch
Dependencies (3)
|
|
3.2.6
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.6
patch
Dependencies (3)
|
|
3.2.5
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.5
patch
Dependencies (3)
|
|
3.2.4
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.4
patch
Dependencies (3)
|
|
3.2.3
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.3
patch
Dependencies (3)
|
|
3.2.2
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.2
patch
Dependencies (3)
|
|
3.2.1
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.1
patch
Dependencies (3)
|
|
3.2.0
minor
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (3)
|
|
3.1.3
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.3
patch
Dependencies (4)
|
|
3.1.2
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (4)
|
|
2.5.5
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.5
patch
Dependencies (3)
|
|
3.1.1
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (4)
|
|
3.1.0
minor
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (4)
|
|
2.5.4
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.4
patch
Dependencies (3)
|
|
2.5.3
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.3
patch
Dependencies (3)
|
|
3.0.2
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (4)
|
|
2.5.2
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (3)
|
|
3.0.1
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (4)
|
|
2.5.1
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (3)
|
|
2.5.0
minor
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (3)
|
|
3.0.0
major
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (4)
|
|
2.4.4
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.4
patch
Dependencies (3)
|
|
2.4.3
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.3
patch
Dependencies (3)
|
|
2.4.2
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.2
patch
Dependencies (3)
|
|
2.4.1
patch
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.1
patch
Dependencies (3)
|
|
2.4.0
minor
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (3)
|
|
2.3.0
minor
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (3)
|
|
2.2.0
initial
1 CVE
CVE-2026-50202
GHSA-7fqc-p256-7pwj
Jul 02, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated
5.9
/ 10
Medium
Network
High
High
None
Unchanged
High
High
None
SummaryThe JWT signing key cache in ImpactIn multi-scheme deployments, an attacker who controls one identity provider's signing key can forge tokens accepted by other schemes within the same application. For all applications using MitigationsIf an immediate upgrade is not possible:
Affected versions
2.2.0
2.2.0-rc1
2.2.0-rc2
2.3.0
2.3.0-rc1
2.3.0-rc2
2.4.0
2.4.0-rc1
2.4.1
2.4.2
2.4.3
2.4.4
+ 30 more Show less
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
3.0.0
3.0.0-m1
3.0.0-m2
3.0.0-m3
3.0.0-rc1
3.0.1
3.0.2
3.1.0
3.1.0-rc1
3.1.0-rc2
3.1.1
3.1.2
3.1.3
3.2.0
3.2.0-rc1
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
Fixed in
3.4.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
2.2.0
initial
Dependencies (3)
|