NuGet package
microsoft.openapi.kiota.builder
pkg:nuget/microsoft.openapi.kiota.builder
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-105796 | Hig | 8.8 | >= 0.5.0, < 1.35.0 | 1.35.0 | Oct 6, 2026 | Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlle | |
| CVE-2026-105795 | Low | 3.1 | >= 1.25.1, < 1.35.0 | 1.35.0 | Oct 6, 2026 | Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value |
- affected >= 0.5.0, < 1.35.0fixed 1.35.0
Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlle
- affected >= 1.25.1, < 1.35.0fixed 1.35.0
Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value