Junglewise Threat Intelligence

CVE-2026-50268: Steeltoe Steeltoe.Configuration.Encryption cryptographic downgrade to PKCS#1 v1.5

CVE-2026-50268 · Severity: low · CVSS 3.1 · Published 2026-06-17

Vendors: NuGet, SteeltoeOSS.

Executive brief

Steeltoe, a library for building cloud-native applications, contains a flaw where it fails to use the requested high-security encryption (OAEP) for configuration data. Instead, it silently falls back to an older, less secure method (PKCS#1 v1.5). While there is currently no known way for an attacker to exploit this in standard setups, it leaves the system vulnerable to advanced cryptographic attacks if the decryption process is ever exposed to unauthorized users.

Technical details

A vulnerability exists in Steeltoe.Configuration.Encryption (versions 4.0.0 to 4.1.0) where configuring 'encrypt:rsa:algorithm=OAEP' fails to enable OAEP padding. Due to an incorrect BouncyCastle transformation string, the library silently defaults to PKCS#1 v1.5. While currently mitigated by the fact that decryption is typically performed only on operator-controlled data, this flaw creates a potential Bleichenbacher side-channel vulnerability if a decryption oracle were to be exposed. The issue is resolved in version 4.2.0, though users must re-encrypt existing ciphertexts as the fix changes the required padding for decryption.

Affected products

  • SteeltoeOSS Steeltoe.Configuration.Encryption >= 4.0.0, <= 4.1.0

Timeline

  • 2026-05-29: disclosed: Initial disclosure by maintainers
  • 2026-06-17: advisory: NVD published date
  • 2026-07-02: patched: GitHub Advisory published/reviewed

References