GHSA-67c9-f6v2-qv86
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
Quick fix
GHSA-67c9-f6v2-qv86 — Steeltoe.Discovery.Consul: upgrade to the fixed version with the command below.
dotnet add package Steeltoe.Discovery.Consul --version 4.3.0Details
## Summary
Steeltoe's Consul discovery client parses the `secure` metadata field on each registered service instance using `bool.Parse`, which throws on any value other than `true` or `false`. A single service instance registered with a malformed `secure` value (for example `yes` or `1`) aborts construction of the entire instance list for that service, making the service undiscoverable. When `GetAllInstancesAsync` is used, one malformed instance in any service can abort enumeration across all services. This is the same "one malformed field aborts the whole batch" availability class as [CVE-2026-50196](https://github.com/advisories/GHSA-j8ph-6fxj-g533), but affecting the Consul discovery client.
## Impact
Any principal that can register a service in the Consul catalog can trigger a service-discovery outage for all Steeltoe applications resolving that service. The outage affects all instances of the targeted service — not just the malformed one — and persists until the offending registration is removed.
## Affected configuration
- Application uses `ConsulDiscoveryClient` (any deployment). - The Consul catalog contains at least one service instance with a `secure` metadata value that is not `true` or `false`. - Mixed-platform environments where non-.NET clients register services with non-standard metadata values are more likely to encounter this condition.
## Mitigations
If an immediate upgrade is not possible:
- Audit the Consul catalog for service registrations with non-standard `secure` metadata values. - Restrict write access to the Consul service registration API to trusted services.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.0.0Fixed in: 4.3.0dotnet add package Steeltoe.Discovery.Consul --version 4.3.0References
- https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-67c9-f6v2-qv86[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-81516[ADVISORY]
- https://github.com/SteeltoeOSS/Steeltoe/commit/028569c4f4f0e9e393e3c22a4fa5d07987dd8673[WEB]
- https://github.com/SteeltoeOSS/Steeltoe/releases/tag/4.3.0[WEB]
- https://github.com/SteeltoeOSS/security-advisories[PACKAGE]