Description
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the X-Client-Cert request header without proving possession of the corresponding private key. Common Cloud Foundry routers do not remove this header from inbound requests. When inbound requests are not restricted to a known trusted proxy source IP, an attacker who obtains the public certificate of an application instance in the target organization or space and can reach the application can spoof X-Client-Cert to bypass the SameOrg and SameSpace policies for the certificate validity period. This issue is fixed in version 4.3.0.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Impersonation via header spoofing that bypasses SameOrg and SameSpace policies
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in Steeltoe.Security.Authorization.Certificate, which accepts the X-Client-Cert header without verifying that the requester holds the corresponding private key. This allows an attacker who knows the public certificate of an application instance to send requests with a forged X-Client-Cert header and bypass SameOrg and SameSpace access controls during the certificate’s validity period. The weakness stems from missing authentication of the private key (CWE-288) and improper use of certificate information (CWE-295).

Affected Systems

Affected products are parts of the Steeltoe open‑source framework used for building cloud‑native applications. The issue exists in all releases prior to 4.3.0 of Steeltoe, particularly the components that implement AddOrgAndSpacePolicies() and UseCertificateAuthorization().

Risk and Exploitability

With a CVSS score of 6.5 and no EPSS data available, the vulnerability is considered medium severity. The vulnerability can be exploited by any attacker who can obtain the public certificate of a target application instance and has network reachability to that instance, provided inbound requests are not filtered to a trusted proxy source. The issue is not listed in the CISA KEV catalog, indicating that publicly known exploits have not yet been reported. However, the attack vector is plausible because common Cloud Foundry routers retain the X-Client-Cert header, and the lack of private‑key proof makes the spoof straightforward.

Generated by OpenCVE AI on September 17, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Steeltoe to version 4.3.0 or later, which implements proper private‑key validation.
  • Configure the environment or application to only allow inbound X‑Client‑Cert headers from trusted proxy IPs, blocking spoofed requests from untrusted sources.
  • If upgrading is not immediately possible, remove or disable the UseCertificateAuthorization() feature and revert to alternative authentication mechanisms to prevent the header from being trusted.

Generated by OpenCVE AI on September 17, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5mq7-rwhj-4fh9 Steeltoe: Header-forwarded client cert lacks proof of private-key possession
History

Fri, 25 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Steeltoeoss
Steeltoeoss security-advisories
Vendors & Products Steeltoeoss
Steeltoeoss security-advisories

Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the X-Client-Cert request header without proving possession of the corresponding private key. Common Cloud Foundry routers do not remove this header from inbound requests. When inbound requests are not restricted to a known trusted proxy source IP, an attacker who obtains the public certificate of an application instance in the target organization or space and can reach the application can spoof X-Client-Cert to bypass the SameOrg and SameSpace policies for the certificate validity period. This issue is fixed in version 4.3.0.
Title Steeltoe: Header-forwarded client cert lacks proof of private-key possession
Weaknesses CWE-288
CWE-295
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Steeltoeoss Security-advisories
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-23T18:46:54.265Z

Reserved: 2026-08-27T17:48:42.118Z

Link: CVE-2026-81868

cve-icon Vulnrichment

Updated: 2026-09-23T18:42:42.539Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:17:47.607

Modified: 2026-09-30T17:31:44.573

Link: CVE-2026-81868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:48:02Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel

  • CWE-295

    Improper Certificate Validation