CVE-2026-76905
kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed non-string scalar field in a multipart/form-data request body produces a nested ParseError with a nil RequestError.Parameter, and applications that render the validation error through openapi3filter.ConvertErrors or ValidationErrorEncoder panic. An unauthenticated client can repeatedly send such requests to deny service when the application lacks a recovery boundary. JSON request bodies and applications that do not use these error-rendering helpers are not affected. This issue is fixed in version 0.141.0.
Properties
- summary
- kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
- severity
- HIGH
- epss_score
- 0.00609
- cvss_severity
- HIGH
- cvss_score
- 7.5
- retrieved_at
- 2026-10-05T10:42:26+00:00
- ghsa_published
- 2026-08-21T20:55:46Z
- source_url
- https://github.com/advisories/GHSA-mmfr-pmjx-hw9w
- ghsa_updated
- 2026-08-21T20:55:47Z
- ghsa_id
- GHSA-mmfr-pmjx-hw9w
- score
- 7.5
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-76905
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- is_ghsa_only
- false
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- published_at
- 2026-08-21T21:17:06.320
- last_modified
- 2026-09-09T21:06:39.057
- epss_percentile
- 0.47325
Related Entities (6)
DESCRIBED_BY (1)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph