highCVSS 7.5Vulnerability

CVE-2026-50200

### Summary The `Sanitizer` component in the Environment actuator redacts configuration values by matching the configuration key name against a suffix list. The default list (`password`, `secret`, `key`, `token`, `.*credentials.*`, `vcap_services`) does not cover the standard .NET pattern `ConnectionStrings:<name>` or Steeltoe Connectors' `Steeltoe:Client:<type>:Default:ConnectionString`. There is no value-based scrubbing, so full connection string values including embedded `Password=` and `user:pass@host` segments are returned verbatim in `/actuator/env` responses. ### Impact Any caller who can reach `/actuator/env` can receive connection strings containing plaintext credentials. Those credentials enable direct connection to the backing database, bypassing the application tier. ### Affected configuration - Application configuration contains credentials in `ConnectionStrings:*` or `*:ConnectionString` keys. - On standard deployments: `env` is added to `Management:Endpoints:Actuator:Exposure:Include`. This is not the default. - On Cloud Foundry: the `/cloudfoundryapplication/env` path is accessible to any authenticated CF user with `read_basic_data` permissions (Space Auditor and above) regardless of the exposure configuration. ### Mitigations If an immediate upgrade is not possible: - On the standard path, remove `env` from the actuator exposure list. - Add `.*connectionstring.*` to `KeysToSanitize` as a defense-in-depth measure for both paths. - Require authorization on actuator endpoints.

Properties

summary
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
severity
high
epss_score
0.00185
cvss_score
7.5
ghsa_published
2026-07-02T20:31:11Z
source_url
https://github.com/advisories/GHSA-q62h-354g-5r85
ghsa_updated
2026-07-02T20:31:13Z
ghsa_id
GHSA-q62h-354g-5r85
cve_id
CVE-2026-50200
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
is_ghsa_only
false
epss_percentile
0.08391

Related Entities (8)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (2)

[Software]nuget/Steeltoe.Management.Endpoint
[Software]nuget/Steeltoe.Management.EndpointCore

AFFECTS (2)

[Software]nuget/Steeltoe.Management.EndpointCore
[Software]nuget/Steeltoe.Management.Endpoint

HAS_WEAKNESS (2)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
[Weakness]Cleartext Transmission of Sensitive Information

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-50200 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal