๐Ÿ” CVE Alert

CVE-2026-50268

LOW 1.9

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

CVSS Score
1.9
EPSS Score
0.0%
EPSS Percentile
0th

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the `OAEP` setting selects PKCS#1 v1.5, which is the same algorithm as the `DEFAULT` setting. Steeltoe.Configuration.Encryption version 4.2.0 patches the issue.

CWE CWE-256 CWE-327
Vendor steeltoeoss
Product steeltoe.configuration.encryption
Published Jun 17, 2026
Stay Ahead of the Next One

Get instant alerts for steeltoeoss steeltoe.configuration.encryption

Be the first to know when new low vulnerabilities affecting steeltoeoss steeltoe.configuration.encryption are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

SteeltoeOSS / Steeltoe.Configuration.Encryption
>= 4.0.0, < 4.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-4j9m-h44m-2hv8 github.com: https://github.com/SteeltoeOSS/Steeltoe/commit/6cfee5cccddf8f9a31de69b0ca5ccdd771b73e5b