VYPR

Go modules package

github.com/getkin/kin-openapi

pkg:golang/github.com/getkin/kin-openapi

Vulnerabilities (2)

  • CVE-2026-73502Jul 24, 2026
    affected < 0.144.0fixed 0.144.0

    | Field | Value | |---|---| | Ecosystem | Go | | Package | `github.com/getkin/kin-openapi` | | Affected versions | `<= 0.143.0` (introduced in `v0.2.0`, PR #90, 2019-05-07; reproduced on `HEAD` `30e2923`) | | Patched versions | 0.144.0 | --- ### Summary `openapi3filter.Validate

  • CVE-2025-30153HigMar 19, 2025
    affected < 0.131.0fixed 0.131.0

    kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system