CVE-2026-75523: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in SteeltoeOSS security-advisories
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query strings. When Management:Endpoints:HttpExchanges:IncludeQueryString is enabled, the HttpExchangeRequest response can disclose OAuth tokens, password-reset tokens, signed-URL signatures, API keys, and other query-string secrets from prior traffic to a caller that can reach the explicitly exposed endpoint. The Steeltoe.Management.Endpoint.Actuators.HttpExchanges DEBUG logger also records these URIs, creating a second disclosure channel for users with log access. This issue is fixed in version 4.3.0.
AI Analysis
Technical Summary
SteeltoeOSS versions before 4.3.0 have a vulnerability in the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint. While the MaskedUri function masks user information in URIs, it does not inspect or mask query string parameters. If the Management:Endpoints:HttpExchanges:IncludeQueryString setting is enabled, sensitive data contained in query strings from prior HTTP traffic can be disclosed to any caller able to access this endpoint. Furthermore, the DEBUG logger records these URIs, potentially exposing sensitive tokens and keys to users with log access. This vulnerability is addressed in SteeltoeOSS version 4.3.0.
Potential Impact
An attacker who can access the /actuator/httpexchanges endpoint with IncludeQueryString enabled may obtain sensitive information such as OAuth tokens, password-reset tokens, signed-URL signatures, and API keys from previous HTTP requests. This exposure can lead to unauthorized access or misuse of these credentials. Additionally, sensitive data may be exposed through DEBUG logs accessible to users with log access privileges. The vulnerability does not affect system integrity or availability but compromises confidentiality.
Mitigation Recommendations
This vulnerability is fixed in SteeltoeOSS version 4.3.0. Users should upgrade to version 4.3.0 or later to remediate the issue. If upgrading is not immediately possible, disabling the Management:Endpoints:HttpExchanges:IncludeQueryString setting will prevent query string data from being included in the endpoint response, mitigating the exposure. Review and restrict access to DEBUG logs to prevent sensitive data disclosure through logging.
CVE-2026-75523: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in SteeltoeOSS security-advisories
Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query strings. When Management:Endpoints:HttpExchanges:IncludeQueryString is enabled, the HttpExchangeRequest response can disclose OAuth tokens, password-reset tokens, signed-URL signatures, API keys, and other query-string secrets from prior traffic to a caller that can reach the explicitly exposed endpoint. The Steeltoe.Management.Endpoint.Actuators.HttpExchanges DEBUG logger also records these URIs, creating a second disclosure channel for users with log access. This issue is fixed in version 4.3.0.
CVSS v3.1
Score 5.9medium
Affected software
SteeltoeOSS
security-advisories
pkg:nuget/steeltoe.management.endpointRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SteeltoeOSS versions before 4.3.0 have a vulnerability in the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint. While the MaskedUri function masks user information in URIs, it does not inspect or mask query string parameters. If the Management:Endpoints:HttpExchanges:IncludeQueryString setting is enabled, sensitive data contained in query strings from prior HTTP traffic can be disclosed to any caller able to access this endpoint. Furthermore, the DEBUG logger records these URIs, potentially exposing sensitive tokens and keys to users with log access. This vulnerability is addressed in SteeltoeOSS version 4.3.0.
Potential Impact
An attacker who can access the /actuator/httpexchanges endpoint with IncludeQueryString enabled may obtain sensitive information such as OAuth tokens, password-reset tokens, signed-URL signatures, and API keys from previous HTTP requests. This exposure can lead to unauthorized access or misuse of these credentials. Additionally, sensitive data may be exposed through DEBUG logs accessible to users with log access privileges. The vulnerability does not affect system integrity or availability but compromises confidentiality.
Mitigation Recommendations
This vulnerability is fixed in SteeltoeOSS version 4.3.0. Users should upgrade to version 4.3.0 or later to remediate the issue. If upgrading is not immediately possible, disabling the Management:Endpoints:HttpExchanges:IncludeQueryString setting will prevent query string data from being included in the endpoint response, mitigating the exposure. Review and restrict access to DEBUG logs to prevent sensitive data disclosure through logging.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-17T20:49:21.600Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aac0b8155bf5e2cf5942ee8
Added to database: 09/17/2026, 15:47:13 UTC
Last enriched: 09/17/2026, 16:02:08 UTC
Last updated: 09/18/2026, 01:12:01 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.