CVE-2026-105796
- EPSS 0.9%
- Veröffentlicht 06.10.2026 14:21:42
- Zuletzt bearbeitet 06.10.2026 16:00:36
Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminato...
CVE-2026-105795
- EPSS 1.21%
- Veröffentlicht 06.10.2026 14:19:03
- Zuletzt bearbeitet 06.10.2026 18:16:47
Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest with...
CVE-2026-73851
- EPSS 1.48%
- Veröffentlicht 17.08.2026 15:16:57
- Zuletzt bearbeitet 18.09.2026 20:09:01
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../.....
CVE-2026-59867
- EPSS 1.92%
- Veröffentlicht 16.07.2026 14:48:11
- Zuletzt bearbeitet 17.08.2026 15:16:57
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-contro...
CVE-2026-59866
- EPSS 1.36%
- Veröffentlicht 16.07.2026 14:46:50
- Zuletzt bearbeitet 17.08.2026 15:16:57
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names a...
CVE-2026-59864
- EPSS 1.28%
- Veröffentlicht 16.07.2026 14:45:36
- Zuletzt bearbeitet 17.08.2026 15:16:56
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabiliti...
CVE-2026-59865
- EPSS 3.19%
- Veröffentlicht 16.07.2026 14:43:40
- Zuletzt bearbeitet 17.08.2026 15:16:56
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and prese...
- EPSS 1.12%
- Veröffentlicht 16.07.2026 14:42:02
- Zuletzt bearbeitet 17.08.2026 15:16:56
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and ki...
CVE-2026-59859
- EPSS 1.02%
- Veröffentlicht 16.07.2026 14:40:27
- Zuletzt bearbeitet 17.08.2026 15:16:56
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDou...
CVE-2026-59862
- EPSS 1.02%
- Veröffentlicht 16.07.2026 14:38:59
- Zuletzt bearbeitet 17.08.2026 15:16:56
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation...