vulns.co
/
GKData.io MCP

Steeltoe · 1 min read

Steeltoe: diagnostic URI masking must cover the complete data contract

CVE-2026-75523 describes diagnostic URI masking that removed inline credentials but preserved query contents. The failed assumption was that sanitizing one URI component made the whole representation safe for secondary consumers. Request secrets could consequently cross into diagnostic responses and DEBUG logs.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: define an explicit retention contract for each diagnostic field, then minimize before storage and fan-out. Check response and logging consumers separately. The advisory identifies 4.3.0 as patched; temporary mitigations include omitting query strings and disabling or authenticating diagnostic exposure.

Before reading

  • HTTP credentials, integration boundaries and secure data handling

Context and limits

  • Affected versions are <=4.2.0. The diagnostic endpoint requires explicit exposure and is not enabled by default; relevant traffic must carry query-string secrets. Log disclosure additionally requires the relevant DEBUG logging.
  • The source describes disclosure to diagnostic readers, not demonstrated production compromise or universal account takeover. It does not detail the patch implementation or release date.
  • The advisory credits manus-use as reporter.

Sources and provenance

  1. Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets Steeltoe · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software