CVE-2026-50201
Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to EndpointPermissions.Restricted, which is mappeds to Cloud Foundry's read_basic_data permission (granted to Space Auditors and similar low-trust roles). Sensitive actuators including heap dump, environment, and thread dump do not raise this to EndpointPermissions.Full, so CF's read_sensitive_data permission flag is not enforced for those endpoints. Spring Boot's equivalent Cloud Foundry integration gates these endpoints with read_sensitive_data by default. Steeltoe.Management.Endpoint 4.2.0 and Steeltoe.Management.EndpointCore 3.4.0 patch the issue. If an immediate upgrade is not possible, explicitly set RequiredPermissions = EndpointPermissions.Full in the options for HeapDumpEndpointOptions, EnvironmentEndpointOptions, and ThreadDumpEndpointOptions; and/or if heap dump, thread dump, or environment are not needed in production, register only the required actuators individually instead of using AddAllActuators().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Steeltoe.Management.EndpointNuGet | < 4.2.0 | 4.2.0 |
Steeltoe.Management.EndpointBaseNuGet | < 3.4.0 | 3.4.0 |
Affected products
2- Range: <4.2.0
- Range: <4.2.0, <3.4.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-227r-jm2g-7cp4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-50201ghsaADVISORY
- github.com/SteeltoeOSS/Steeltoe/commit/b39defa4db5f44f8696c456866b3a5b900d8d96bnvdWEB
- github.com/SteeltoeOSS/Steeltoe/commit/da6c604decd992f61aeef763f5814102dcb088c7nvdWEB
- github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-227r-jm2g-7cp4nvdWEB
News mentions
0No linked articles in our index yet.