MEDIUM 6.0 NVD
CVE-2026-53508
oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did no
oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from a git revision (the rev:path form, e.g. main:openapi.yaml). External $refs were resolved on that load path even when external refs were explicitly disabled, so the mitigation silently did not apply there. This issue has been patched in version 1.18.1.
References
- https://github.com/oasdiff/oasdiff/pull/832
- https://github.com/oasdiff/oasdiff/pull/974
- https://github.com/oasdiff/oasdiff/pull/975
- https://github.com/oasdiff/oasdiff/security/advisories/GHSA-2jcc-mxv7-p3f9
This medium severity vulnerability with a CVSS score of 6.0 was published on 2026-08-31 via NVD.
vulnfeed aggregates 11540 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.