PT-2026-94381 · Steeltoe · Steeltoe

·

CVE-2026-75523

·

Published

2026-09-17

·

Updated

2026-09-23

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Steeltoe versions prior to 4.3.0
Description The /actuator/httpexchanges endpoint processes recorded request URIs using MaskedUri, which only masks user information and ignores query strings. When the Management:Endpoints:HttpExchanges:IncludeQueryString setting is enabled, the HttpExchangeRequest response may disclose sensitive data from previous traffic, such as OAuth tokens, password-reset tokens, signed-URL signatures, and API keys, to any caller with access to the endpoint. Additionally, the Steeltoe.Management.Endpoint.Actuators.HttpExchanges DEBUG logger records these URIs, providing another channel for sensitive data disclosure to users with log access.
Recommendations Update to version 4.3.0. Remove httpexchanges from the actuator exposure list or restrict it behind authentication. Set Management:Endpoints:HttpExchanges:IncludeQueryString to false to remove query strings from recorded exchanges.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75523
GHSA-8PHW-XRJ9-CPQP

Affected Products

Steeltoe