CVE-2026-53508
Last modified
CVE-2026-53508 is a medium-severity vulnerability rated 6/10 on the CVSS scale. oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from a git revision (the rev:path form, e.g. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from a git revision (the rev:path form, e.g. main:openapi.yaml). External $refs were resolved on that load path even when external refs were explicitly disabled, so the mitigation silently did not apply there. This issue has been patched in version 1.18.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| oasdiff | oasdiff | >= 1.13.2, < 1.18.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53508?
How severe is CVE-2026-53508?
How do I fix CVE-2026-53508?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53501Thumbor is an open-source photo thumbnail service by globo.c…8.2
- CVE-2026-53502Thumbor is an open-source photo thumbnail service by globo.c…8.7
- CVE-2026-53503Thumbor is an open-source photo thumbnail service by globo.c…7.5
- CVE-2026-53504Thumbor is an open-source photo thumbnail service by globo.c…7.5
- CVE-2026-53505Thumbor is an open-source photo thumbnail service by globo.c…7.5
- CVE-2026-53507oasdiff-action is a GitHub Action that detects breaking chan…8.3
- CVE-2026-53509CKAN MCP Server is a tool for querying CKAN open data portal…5.7
- CVE-2026-5351A weakness has been identified in Trendnet TEW-657BRM 1.00.1…8.8
- CVE-2026-53510Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon:…8.1
- CVE-2026-53511calibre is an e-book manager. Prior to 9.10.0, a malicious E…8.5
- CVE-2026-53512Better Auth is an authentication and authorization library f…9.1
- CVE-2026-53513Better Auth is an authentication and authorization library f…9.6
Are you affected by CVE-2026-53508?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
