CVE-2026-49451 - High Severity Vulnerability
Vulnerable Library - microsoft.openapi.2.4.1.nupkg
.NET models with JSON and YAML writers for OpenAPI specification
Library home page: https://api.nuget.org/packages/microsoft.openapi.2.4.1.nupkg
Sample Path to Dependency File: /src/SharpConnector.Api/SharpConnector.Api.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.openapi/2.4.1/microsoft.openapi.2.4.1.nupkg
Dependency Hierarchy:
- swashbuckle.aspnetcore.10.1.7.nupkg (Root Library)
- swashbuckle.aspnetcore.swaggergen.10.1.7.nupkg
- swashbuckle.aspnetcore.swagger.10.1.7.nupkg
- ❌ microsoft.openapi.2.4.1.nupkg (Vulnerable Library)
Found in base branch: main
Vulnerability Details
The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From 2.0.0-preview11 until 2.7.5 and 3.5.4, a small OpenAPI document containing a circular schema reference can cause process termination through stack overflow in Microsoft.OpenApi. The issue affects OpenAPI document parsing through public OpenAPI.NET reader APIs and has been confirmed across both JSON and YAML reader paths. This vulnerability is fixed in 2.7.5 and 3.5.4.
Publish Date: 2026-06-30
URL: CVE-2026-49451
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-v5pm-xwqc-g5wc
Release Date: 2026-06-30
Fix Resolution: microsoft.openapi - 2.7.5,microsoft.openapi - 3.5.4
Step up your Open Source Security Game with Mend here
CVE-2026-49451 - High Severity Vulnerability
.NET models with JSON and YAML writers for OpenAPI specification
Library home page: https://api.nuget.org/packages/microsoft.openapi.2.4.1.nupkg
Sample Path to Dependency File: /src/SharpConnector.Api/SharpConnector.Api.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.openapi/2.4.1/microsoft.openapi.2.4.1.nupkg
Dependency Hierarchy:
Found in base branch: main
The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From 2.0.0-preview11 until 2.7.5 and 3.5.4, a small OpenAPI document containing a circular schema reference can cause process termination through stack overflow in Microsoft.OpenApi. The issue affects OpenAPI document parsing through public OpenAPI.NET reader APIs and has been confirmed across both JSON and YAML reader paths. This vulnerability is fixed in 2.7.5 and 3.5.4.
Publish Date: 2026-06-30
URL: CVE-2026-49451
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: GHSA-v5pm-xwqc-g5wc
Release Date: 2026-06-30
Fix Resolution: microsoft.openapi - 2.7.5,microsoft.openapi - 3.5.4
Step up your Open Source Security Game with Mend here