Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, ConsulDiscoveryClient constructs ConsulServiceInstance objects by parsing each registration's secure metadata with a strict Boolean conversion. A principal that can register a Consul service can supply a secure value other than true or false, causing the exception from one instance to abort construction of the entire instance list and make the targeted service undiscoverable. When GetAllInstancesAsync enumerates all services, one malformed instance can abort enumeration across every service. The outage persists until the offending registration is removed. This issue is fixed in version 4.3.0.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service to service discovery
Action: Immediate Patch
AI Analysis

Impact

A bug in Steeltoe's Consul discovery client causes the construction of service instances to fail when an instance registers an invalid value in its secure metadata. Because the Boolean conversion is strict, any value other than "true" or "false" triggers an exception that aborts the entire instance list assembly. Consequently, the service that registered the malformed entry becomes unavailable, and subsequent calls to enumerate all services are halted, leading to a global outage of the Consul‑based discovery until the problematic registration is removed.

Affected Systems

The issue affects Steeltoe OSS deployments using the Consul discovery component from version 4.0.0 through 4.3.0. Administrators of applications built with these libraries and relying on Consul for service discovery are impacted until they upgrade past 4.3.0.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The exploitability depends on the attacker’s ability to register a service in Consul; only principals with registration rights can supply the malformed secure metadata. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting that known, widespread exploitation has not been observed. Nonetheless, an attacker with sufficient permissions can cause a denial of service that persists until the offending registration is deleted.

Generated by OpenCVE AI on September 17, 2026 at 20:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Steeltoe to version 4.3.0 or later to apply the vendor fix.
  • Remove or correct the malformed secure metadata value from the offending Consul registration.
  • Implement validation to ensure that any secure metadata values supplied during registration are strictly "true" or "false" to prevent future malformed entries.

Generated by OpenCVE AI on September 17, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-67c9-f6v2-qv86 Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Steeltoeoss
Steeltoeoss security-advisories
Vendors & Products Steeltoeoss
Steeltoeoss security-advisories

Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, ConsulDiscoveryClient constructs ConsulServiceInstance objects by parsing each registration's secure metadata with a strict Boolean conversion. A principal that can register a Consul service can supply a secure value other than true or false, causing the exception from one instance to abort construction of the entire instance list and make the targeted service undiscoverable. When GetAllInstancesAsync enumerates all services, one malformed instance can abort enumeration across every service. The outage persists until the offending registration is removed. This issue is fixed in version 4.3.0.
Title Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
Weaknesses CWE-755
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Steeltoeoss Security-advisories
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:19:01.075Z

Reserved: 2026-08-26T20:58:58.084Z

Link: CVE-2026-81516

cve-icon Vulnrichment

Updated: 2026-09-17T17:06:10.538Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:17:46.930

Modified: 2026-09-30T17:31:44.573

Link: CVE-2026-81516

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:48:00Z

Weaknesses
  • CWE-755

    Improper Handling of Exceptional Conditions