Improper Handling of Exceptional Conditions Affecting steeltoe.discovery.consul package, versions [4.0.0,4.3.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.61% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-STEELTOEDISCOVERYCONSUL-20079555
  • published24 Sept 2026
  • disclosed17 Sept 2026
  • creditmanus-use

Introduced: 17 Sep 2026

NewCVE-2026-81516  (opens in a new tab)
CWE-755  (opens in a new tab)

How to fix?

Upgrade Steeltoe.Discovery.Consul to version 4.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of Exceptional Conditions due to the ConsulServiceInstance parsing of Consul service metadata in src/Discovery/src/Consul/ConsulServiceInstance.cs. An attacker can abort service instance lookup by registering a service instance with a malformed secure metadata value such as yes or 1. When Steeltoe resolves that service, bool.Parse throws while building the instance list, making the targeted service undiscoverable and, when enumerating all instances, stopping discovery across the batch.

Workarounds

  • Audit the Consul catalog for service registrations with non-standard secure metadata values, and remove or correct entries whose secure field is not true or false; this prevents malformed registrations from aborting Steeltoe service-instance lookup and blocking discovery.
  • Restrict write access to the Consul service registration API to trusted services only; this prevents untrusted principals from registering malformed secure metadata that can trigger the denial of service.

CVSS Base Scores

version 4.0
version 3.1