Impact
A bug in Steeltoe's Consul discovery client causes the construction of service instances to fail when an instance registers an invalid value in its secure metadata. Because the Boolean conversion is strict, any value other than "true" or "false" triggers an exception that aborts the entire instance list assembly. Consequently, the service that registered the malformed entry becomes unavailable, and subsequent calls to enumerate all services are halted, leading to a global outage of the Consul‑based discovery until the problematic registration is removed.
Affected Systems
The issue affects Steeltoe OSS deployments using the Consul discovery component from version 4.0.0 through 4.3.0. Administrators of applications built with these libraries and relying on Consul for service discovery are impacted until they upgrade past 4.3.0.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The exploitability depends on the attacker’s ability to register a service in Consul; only principals with registration rights can supply the malformed secure metadata. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting that known, widespread exploitation has not been observed. Nonetheless, an attacker with sufficient permissions can cause a denial of service that persists until the offending registration is deleted.
OpenCVE Enrichment
Github GHSA