github.com/getkin/kin-openapi
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/getkin/kin-openapipage 1 of 1
- CVE-2025-30153HIGHCVSS 7.5EG 7.5✓ Fixed in 0.131.02025-03-19
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing t…
- CVE-2026-73501CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.144.02026-08-12
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without ch…
- CVE-2026-76905HIGHCVSS 7.5EG 7.5✓ Fixed in 0.141.02026-08-21
kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A ma…
- CVE-2026-77354HIGHCVSS 8.7EG 8.7✓ Fixed in 0.142.02026-08-21
kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter into a d…
Check whether github.com/getkin/kin-openapi is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/getkin/kin-openapi CVEs against the assets you own.
Start Free Scan →