PT-2026-50568 · Steeltoe · Steeltoe.Configuration.Encryption

·

CVE-2026-50268

·

Published

2026-06-17

·

Updated

2026-07-02

CVSS v3.1

1.9

Low

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Steeltoe.Configuration.Encryption versions 4.0.0 through 4.1.0
Description Steeltoe is an open source project providing libraries for building cloud-native applications. An issue exists where configuring the encrypt:rsa:algorithm variable with the value OAEP fails to enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the OAEP setting instead selects PKCS#1 v1.5, which is the same algorithm used by the DEFAULT setting.
Recommendations Update Steeltoe.Configuration.Encryption to version 4.2.0.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50268
GHSA-4J9M-H44M-2HV8

Affected Products

Steeltoe.Configuration.Encryption