Microsoft.OpenApi.Kiota.Builder
NuGet10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Microsoft.OpenApi.Kiota.Builderpage 1 of 1
- CVE-2026-41134HIGHCVSS 7.8EG 7.8✓ Fixed in 1.29.12026-04-22
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/que…
- CVE-2026-59859HIGHCVSS 8.7EG 8.7✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through …
- CVE-2026-59860HIGHCVSS 8.7EG 8.7✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDoc…
- CVE-2026-59861HIGHCVSS 7.5EG 7.5✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLit…
- CVE-2026-59862HIGHCVSS 7.5EG 7.5✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Do…
- CVE-2026-59863HIGHCVSS 7.0EG 7.0✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client gene…
- CVE-2026-59864CRITICALCVSS 9.3EG 9.3✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai…
- CVE-2026-59865CRITICALCVSS 9.3EG 9.3✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI descriptio…
- CVE-2026-59866CRITICALCVSS 9.3EG 9.3✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namesp…
- CVE-2026-59867HIGHCVSS 7.1EG 7.1✓ Fixed in 1.29.12026-07-16
vulnerable: 0.2.0-preview ... 1.9.1 (46 versions)
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an atta…
Check whether Microsoft.OpenApi.Kiota.Builder is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Microsoft.OpenApi.Kiota.Builder CVEs against the assets you own.
Start Free Scan →