THREAT OPS › Threat News › [GHSA] GHSA-5mq7-rwhj-4fh9 (medium) — Steeltoe: Header-forwarded client cert lacks proof of private-key possession
[GHSA] GHSA-5mq7-rwhj-4fh9 (medium) — Steeltoe: Header-forwarded client cert lacks proof of private-key possession
GHSA-5mq7-rwhj-4fh9 Severity: medium CVE: CVE-2026-81868
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
### Summary
When Steeltoe's certificate-based authorization (`UseCertificateAuthorization`) is configured, the default configuration of the middleware relies on the `X-Client-Cert` HTTP header to identify the client certificate, without verifying private-key poss
Indicators of compromise
- CVE-2026-81868cve
Original source: https://github.com/advisories/GHSA-5mq7-rwhj-4fh9