CVE-2026-53508 | oasdiff up to 1.18.0 Loader openapi3.Loader.IsExternalRefsAllowed allow-external-refs server-side request forgery

SecurityVulns

A vulnerability categorized as critical has been discovered in oasdiff up to 1.18.0. This issue affects the function openapi3.Loader.IsExternalRefsAllowed of the component Loader. Such manipulation of the argument allow-external-refs leads to server-side request forgery.

This vulnerability is uniquely identified as CVE-2026-53508. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More