CVE Browser
CVE-2026-53507 HIGH
oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runs
CVSS 8.3 EPSS 0.50% Aug 31, 2026
CVE-2026-53508 MEDIUM
oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)
CVSS 6.0 EPSS 0.50% Aug 31, 2026
Go
Showing 1 to 2 CVEs · page 1