Impact
The vulnerability arises when the Steeltoe discovery client processes a malformed Eureka registry response. An unrecognized actionType, a non‑Boolean isCoordinatingDiscoveryServer value, or a nonnumeric timestamp during deserialization causes the client to abort the entire registry fetch. As a result, all connected clients receive an empty or stale instance list. The weakness corresponds to CWE‑755 and delivers a denial‑of‑service condition by disrupting application instance discovery.
Affected Systems
Affected instances include any application built with Steeltoe Discovery Eureka between version 4.0.0 up to and including 4.2.9. The bug was fixed in Steeltoe release 4.3.0. The issue applies to the Steeltoe OSS project libraries, specifically the EurekaDiscoveryClient and its JSON converters (JsonInstanceInfoConverter, BoolStringJsonConverter, LongStringJsonConverter).
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, but the vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker who can register or update an instance – i.e., a principal with write access to Eureka – to submit malformed registration data. With such access, the attacker can trigger the DoS and force all Steeltoe clients that rely on that registry to experience outages.
OpenCVE Enrichment
Github GHSA