CVE-2026-73501

🟠 Łataj w tym tygodniu

Błąd w kin-openapi umożliwia spełnienie wymagań bezpieczeństwa bez uwierzytelnienia.

CVSS
9.1
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-08-12 22:17:17 UTC
Ostatnia modyfikacja (NVD)2026-09-18 20:09:01 UTC
Referencje