Input validation error in kin-openapi - #VU140576

 

Input validation error in kin-openapi - #VU140576

Published: July 30, 2026


Vulnerability identifier: #VU140576
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the openapi3filter legacy router when handling requests to an existing static path with a non-canonical or unsupported HTTP method. A remote attacker can send a specially crafted request to cause a denial of service.

The panic occurs during route resolution before authentication runs, and exploitation requires the target path to be an exact static path defined in the served specification.


Affected software

kin-openapi

Remediation

Install security update from vendor's website.

kin-openapi - update to 0.145.0

External References

Related Security Bulletins