CVE-2026-50196 PUBLISHED

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

Assigner: GitHub_M
Reserved: 03.06.2026 Published: 17.06.2026 Updated: 18.06.2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 and 3.4.0, DataCenterInfo.FromJson throws ArgumentException for any name value other than "MyOwn" or "Amazon", despite the Java Eureka specification defining a third valid value: "Netflix". The exception propagates through the entire registry deserialization chain and is swallowed by the periodic cache refresh task, leaving the local service registry permanently empty or stale. Versions 4.2.0 and 3.4.0 patch the issue. If an immediate upgrade is not possible, remove any registrations using unsupported DataCenterInfo.name values from the registry. In mixed Java/Spring and Steeltoe environments, audit for the Netflix data center type before deploying Steeltoe Eureka clients.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor SteeltoeOSS
Product Steeltoe.Discovery.Eureka
Versions
  • Version >= 4.0.0, < 4.2.0 is affected
  • Version < 3.4.0 is affected

References

Problem Types

  • CWE-20: Improper Input Validation CWE
  • CWE-400: Uncontrolled Resource Consumption CWE