PT-2026-94382 · Steeltoe · Steeltoe
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Steeltoe versions 4.0.0 through 4.2.9
Description
Steeltoe's
EurekaDiscoveryClient deserializes the registry response as a single unit. If a registered instance contains a field value that cannot be parsed, the deserialization of the entire registry fails. This occurs when there is an unrecognized actionType or status, a non-Boolean value for isCoordinatingDiscoveryServer, or a non-numeric timestamp. Consequently, all connected Steeltoe clients receive an empty or stale instance list until the malformed registration is removed. The affected parsing paths include JsonInstanceInfoConverter, BoolStringJsonConverter, and LongStringJsonConverter. A principal capable of registering or updating an instance can trigger a service-discovery outage for all Steeltoe applications connected to the same registry.Recommendations
Update to version 4.3.0.
Audit the Eureka registry for registrations containing non-standard field values, especially those from non-.NET clients.
Restrict write access to the Eureka registration API to trusted services.
Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Steeltoe