Tim Hess
10 exploits
Active since Jun 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVSS 8.2
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVSS 7.5
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVSS 7.5
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVSS 6.5
Steeltoe's static JWKS cache shared across schemes and never invalidated
CVSS 5.9
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVSS 8.2
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVSS 7.5
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVSS 7.5
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVSS 6.5
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
CVSS 1.9