VYPR

Go modules package

github.com/getkin/kin-openapi

pkg:golang/github.com/getkin/kin-openapi

Vulnerabilities (2)

  • CVE-2026-73502MedAug 18, 2026
    affected < 0.144.0fixed 0.144.0

    kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/json media type has no schema. In openapi3f

  • CVE-2025-30153HigMar 19, 2025
    affected < 0.131.0fixed 0.131.0

    kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system