VYPR
Vendor

Steeltoeoss

Products
8
CVEs
8
Across products
15
Status
Private

Products

8

Recent CVEs

8
  • CVE-2026-50194HigJun 17, 2026
    risk 0.46cvss 8.2epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is…

  • CVE-2026-50200HigJun 17, 2026
    risk 0.42cvss 7.5epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` component in the…

  • CVE-2026-50196HigJun 17, 2026
    risk 0.42cvss 7.5epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 and 3.4.0, `DataCenterInfo.FromJson` throws `ArgumentException` for any `name` value other than…

  • CVE-2026-50201MedJun 17, 2026
    risk 0.35cvss 6.5epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints…

  • CVE-2026-50202MedJun 17, 2026
    risk 0.31cvss 5.9epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and…

  • CVE-2024-40636MedJul 17, 2024
    risk 0.27cvss 5.3epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka…

  • CVE-2026-50267MedJun 17, 2026
    risk 0.24cvss 4.7epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials,…

  • CVE-2026-50268LowJun 17, 2026
    risk 0.05cvss 1.9epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect…