Improper Validation of Syntactic Correctness of Input Affecting steeltoe.discovery.eureka package, versions [,3.4.0)[4.0.0,4.2.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
EPSS
0.34% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-STEELTOEDISCOVERYEUREKA-17423136
  • published23 Jun 2026
  • disclosed18 Jun 2026
  • creditUnknown

Introduced: 18 Jun 2026

CVE-2026-50196  (opens in a new tab)
CWE-1286  (opens in a new tab)

How to fix?

Upgrade Steeltoe.Discovery.Eureka to version 3.4.0, 4.2.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Validation of Syntactic Correctness of Input through the DataCenterInfo.FromJson parser in the appinfo component. An attacker can force the application to accept a crafted JSON JsonDataCenterInfo record with an unexpected Name value by supplying malicious instance metadata. This lets the attacker inject an invalid or spoofed datacenter identity into instance registration and discovery, causing the consumer to misclassify the instance's source or reject it with a JSON parsing exception. In deployments that trust instance metadata from remote peers, this can break service registration and discovery flows for users relying on Eureka.

CVSS Base Scores

version 4.0
version 3.1