Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query strings. When Management:Endpoints:HttpExchanges:IncludeQueryString is enabled, the HttpExchangeRequest response can disclose OAuth tokens, password-reset tokens, signed-URL signatures, API keys, and other query-string secrets from prior traffic to a caller that can reach the explicitly exposed endpoint. The Steeltoe.Management.Endpoint.Actuators.HttpExchanges DEBUG logger also records these URIs, creating a second disclosure channel for users with log access. This issue is fixed in version 4.3.0.
Published: 2026-09-17
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure of sensitive query-string parameters
Action: Update to 4.3.0
AI Analysis

Impact

The vulnerability resides in Steeltoe's Management.Endpoint. When the HttpExchanges actuator is enabled together with the IncludeQueryString setting, recorded request URIs are returned verbatim through a masking helper that does not filter the query string. Attackers who can reach the /actuator/httpexchanges endpoint may receive OAuth tokens, password‑reset tokens, signed‑URL signatures, API keys, and other secrets that were present in prior traffic, leading to exposure of privileged credentials. The same data may also appear in DEBUG‑level logs, creating an additional leak channel for users with log access.

Affected Systems

The flaw affects Steeltoe OSS projects, specifically any application using a Steeltoe.Management.Endpoint version earlier than 4.3.0 that exposes the /actuator/httpexchanges endpoint with the IncludeQueryString option enabled. Versions 4.3.0 and newer contain the fix and no longer expose this data.

Risk and Exploitability

The CVSS base score is 5.9, classifying the risk as medium. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires network visibility to the actuator endpoint and the IncludeQueryString option to be true. If internal users or external attackers can query /actuator/httpexchanges, they can retrieve stored query strings that may contain confidential tokens, leading to credential compromise. The attack vector is therefore an HTTP request to a publicly or internally reachable actuator URI.

Generated by OpenCVE AI on September 17, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Steeltoe to version 4.3.0 or newer, where the issue is resolved.
  • Disable the Management:Endpoints:HttpExchanges:IncludeQueryString setting (set to false) to prevent query string leakage.
  • Restrict access to the /actuator/httpexchanges endpoint by applying authentication or role‑based access controls so only trusted administrators can query it.
  • Adjust logging levels to prevent DEBUG logs from recording sensitive URLs, or level down the HttpExchange logger.

Generated by OpenCVE AI on September 17, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8phw-xrj9-cpqp Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Steeltoeoss
Steeltoeoss security-advisories
Vendors & Products Steeltoeoss
Steeltoeoss security-advisories

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query strings. When Management:Endpoints:HttpExchanges:IncludeQueryString is enabled, the HttpExchangeRequest response can disclose OAuth tokens, password-reset tokens, signed-URL signatures, API keys, and other query-string secrets from prior traffic to a caller that can reach the explicitly exposed endpoint. The Steeltoe.Management.Endpoint.Actuators.HttpExchanges DEBUG logger also records these URIs, creating a second disclosure channel for users with log access. This issue is fixed in version 4.3.0.
Title Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Steeltoeoss Security-advisories
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T17:23:55.524Z

Reserved: 2026-08-17T20:49:21.600Z

Link: CVE-2026-75523

cve-icon Vulnrichment

Updated: 2026-09-17T17:23:47.791Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:17:41.773

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-75523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:48:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor