Unrated severityNVD Advisory· Published Jun 17, 2026
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
CVE-2026-50268
Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring encrypt:rsa:algorithm=OAEP does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the OAEP setting selects PKCS#1 v1.5, which is the same algorithm as the DEFAULT setting. Steeltoe.Configuration.Encryption version 4.2.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=4.0.0 <=4.1.0
Patches
Vulnerability mechanics
References
2- github.com/SteeltoeOSS/Steeltoe/commit/6cfee5cccddf8f9a31de69b0ca5ccdd771b73e5bmitrex_refsource_MISC
- github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-4j9m-h44m-2hv8mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.