HIGHCVSS 7.5Vulnerability

CVE-2026-76905

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed non-string scalar field in a multipart/form-data request body produces a nested ParseError with a nil RequestError.Parameter, and applications that render the validation error through openapi3filter.ConvertErrors or ValidationErrorEncoder panic. An unauthenticated client can repeatedly send such requests to deny service when the application lacks a recovery boundary. JSON request bodies and applications that do not use these error-rendering helpers are not affected. This issue is fixed in version 0.141.0.

Properties

summary
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
severity
HIGH
epss_score
0.00609
cvss_severity
HIGH
cvss_score
7.5
retrieved_at
2026-10-05T10:42:26+00:00
ghsa_published
2026-08-21T20:55:46Z
source_url
https://github.com/advisories/GHSA-mmfr-pmjx-hw9w
ghsa_updated
2026-08-21T20:55:47Z
ghsa_id
GHSA-mmfr-pmjx-hw9w
score
7.5
last_source
FIRST EPSS
cve_id
CVE-2026-76905
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-11T17:54:59+00:00
is_ghsa_only
false
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-21T21:17:06.320
last_modified
2026-09-09T21:06:39.057
epss_percentile
0.47325

Related Entities (6)

DESCRIBED_BY (1)

→[Source]NVD

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]go/github.com/getkin/kin-openapi

AFFECTS (1)

→[Software]go/github.com/getkin/kin-openapi

HAS_WEAKNESS (1)

→[Weakness]NULL Pointer Dereference

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph