CVE-2026-53508: Oasdiff
Medium severity, CVSS 6.0. EPSS: 0.5% chance of exploitation in the next 30 days.
oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from a git revision (the rev:path form, e.g. main:openapi.yaml). External $refs were resolved on that load path even when external refs were explicitly disabled, so the mitigation silently did not apply there. This issue has been patched in version 1.18.1.
Affected products
- Oasdiff Oasdiff: from 1.13.2, before 1.18.1 (fixed in 1.18.1)
Published 2026-08-31. Last modified 2026-09-09.