THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8phw-xrj9-cpqp (medium) — Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets

[GHSA] GHSA-8phw-xrj9-cpqp (medium) — Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets

medgithub_advisoriesPublished 2026-09-17

GHSA-8phw-xrj9-cpqp Severity: medium CVE: CVE-2026-75523

Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets

## Summary

Steeltoe's `/actuator/httpexchanges` endpoint records and displays request URIs after passing them through `MaskedUri`. The masking only covers the `UserInfo` portion of the URI (inline `user:password@host` credentials) and does not inspect the q

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8phw-xrj9-cpqp