THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5mq7-rwhj-4fh9 (medium) — Steeltoe: Header-forwarded client cert lacks proof of private-key possession

[GHSA] GHSA-5mq7-rwhj-4fh9 (medium) — Steeltoe: Header-forwarded client cert lacks proof of private-key possession

medgithub_advisoriesPublished 2026-09-17

GHSA-5mq7-rwhj-4fh9 Severity: medium CVE: CVE-2026-81868

Steeltoe: Header-forwarded client cert lacks proof of private-key possession

### Summary

When Steeltoe's certificate-based authorization (`UseCertificateAuthorization`) is configured, the default configuration of the middleware relies on the `X-Client-Cert` HTTP header to identify the client certificate, without verifying private-key poss

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5mq7-rwhj-4fh9