VYPR

NuGet package

microsoft.openapi.kiota.builder

pkg:nuget/microsoft.openapi.kiota.builder

Vulnerabilities (2)

  • CVE-2026-105796HigOct 6, 2026
    affected >= 0.5.0, < 1.35.0fixed 1.35.0

    Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlle

  • CVE-2026-105795LowOct 6, 2026
    affected >= 1.25.1, < 1.35.0fixed 1.35.0

    Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value