ghsa-67c9-f6v2-qv86
CVSS 7.5 osv_nuget## Summary Steeltoe's Consul discovery client parses the `secure` metadata field on each registered service instance using `bool.Parse`, which throws on any value other than `true` or `false`. A single service instance registered with a malformed `secure` value (for example `yes` or `1`) aborts construction of the entire instance list for that service, making the service undiscoverable. When `GetAllInstancesAsync` is used, one malformed instance in any service can abort enumeration across all services. This is the same "one malformed field aborts the whole batch" availability class as [CVE-2026-50196](https://github.com/advisories/GHSA-j8ph-6fxj-g533), but affecting the Consul discovery client. ## Impact Any principal that can register a service in the Consul catalog can trigger a service-discovery outage for all Steeltoe applications resolving that service. The outage affects all instances of the targeted service — not just the malformed one — and persists until the offending registration is removed. ## Affected configuration - Application uses `ConsulDiscoveryClient` (any deployment). - The Consul catalog contains at least one service instance with a `secure` metadata value that is not `true` or `false`. - Mixed-platform environments where non-.NET clients register services with non-standard metadata values are more likely to encounter this condition. ## Mitigations If an immediate upgrade is not possible: - Audit the Consul catalog for service registrations with non-standard `secure` metadata values. - Restrict write access to the Consul service registration API to trusted services.
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
- https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-67c9-f6v2-qv86
- https://nvd.nist.gov/vuln/detail/CVE-2026-81516
- https://github.com/SteeltoeOSS/Steeltoe/commit/028569c4f4f0e9e393e3c22a4fa5d07987dd8673
- https://github.com/SteeltoeOSS/Steeltoe/releases/tag/4.3.0
- https://github.com/SteeltoeOSS/security-advisories
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "<= 4.2.0",
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-67c9-f6v2-qv86/GHSA-67c9-f6v2-qv86.json"
},
"package": {
"ecosystem": "NuGet",
"name": "Steeltoe.Discovery.Consul",
"purl": "pkg:nuget/Steeltoe.Discovery.Consul"
},
"ranges": [
{
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.3.0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"4.0.0",
"4.1.0",
"4.2.0"
]
}
],
"aliases": [
"CVE-2026-81516"
],
"database_specific": {
"cwe_ids": [
"CWE-755"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T20:30:54Z",
"nvd_published_at": "2026-09-17T16:17:46Z",
"severity": "HIGH"
},
"details": "## Summary\n\nSteeltoe's Consul discovery client parses the `secure` metadata field on each registered service instance using `bool.Parse`, which throws on any value other than `true` or `false`. A single service instance registered with a malformed `secure` value (for example `yes` or `1`) aborts construction of the entire instance list for that service, making the service undiscoverable. When `GetAllInstancesAsync` is used, one malformed instance in any service can abort enumeration across all services.\nThis is the same \"one malformed field aborts the whole batch\" availability class as [CVE-2026-50196](https://github.com/advisories/GHSA-j8ph-6fxj-g533), but affecting the Consul discovery client.\n\n## Impact\n\nAny principal that can register a service in the Consul catalog can trigger a service-discovery outage for all Steeltoe applications resolving that service. The outage affects all instances of the targeted service — not just the malformed one — and persists until the offending registration is removed.\n\n## Affected configuration\n\n- Application uses `ConsulDiscoveryClient` (any deployment).\n- The Consul catalog contains at least one service instance with a `secure` metadata value that is not `true` or `false`.\n- Mixed-platform environments where non-.NET clients register services with non-standard metadata values are more likely to encounter this condition.\n\n## Mitigations\n\nIf an immediate upgrade is not possible:\n\n- Audit the Consul catalog for service registrations with non-standard `secure` metadata values.\n- Restrict write access to the Consul service registration API to trusted services.",
"id": "GHSA-67c9-f6v2-qv86",
"modified": "2026-09-17T20:45:06.563253507Z",
"published": "2026-09-17T20:30:54Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-67c9-f6v2-qv86"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81516"
},
{
"type": "WEB",
"url": "https://github.com/SteeltoeOSS/Steeltoe/commit/028569c4f4f0e9e393e3c22a4fa5d07987dd8673"
},
{
"type": "WEB",
"url": "https://github.com/SteeltoeOSS/Steeltoe/releases/tag/4.3.0"
},
{
"type": "PACKAGE",
"url": "https://github.com/SteeltoeOSS/security-advisories"
}
],
"schema_version": "1.9.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)"
}