📖 8 min read (~ 1700 words).

Security advisories

Security advisories and code scanning alerts on all go-openapi and go-swagger repositories: reporters, severities and the releases that fixed them, refreshed daily.

Advisories still under analysis (triage or draft) are only counted, not disclosed. We keep as few of them as we can.

Summary

RepoPublished advisoriesUnder analysisFixed alertsFixed, not releasedDismissed alertsOpen alerts
go-openapi
analysis0—11—200
ci-workflows0—14—30
codegen0—6——0
codescan0—39—10
doc-site0—3——0
errors0—4—20
go-yaml0—153——⚠️ 6
inflect0—3—10
jsonpointer2—5——0
jsonreference1—7—20
loads0—20—20
runtime0—36—30
spec4—4—20
strfmt0—23—30
swag2—10——0
testify0—7——0
validate0⚠️ 231—20
go-openapi total923760416
go-swagger
dockerctl0—2——⚠️ 2
examples0—11——0
go-swagger9—46—15⚠️ 2
go-swagger total90590154
Grand total18243505610

Detailed report

ItemReporter / sourceSeverityStatusFixed inDate
go-openapi/analysis
9 fixed alerts: GO-2026-5025, GO-2026-5026, GO-2026-5027, GO-2026-5028, GO-2026-5029, GO-2026-5030, GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.25.22026-06-02
1 fixed alert: GO-2026-4559govulncheckunratedfixedv0.25.02026-03-17
1 fixed alert: actions/missing-workflow-permissionsCodeQLmediumfixedv0.24.22025-12-15
20 dismissed alerts——false positive: 20——
go-openapi/ci-workflows
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.3.52026-06-07
11 fixed alerts: actions/untrusted-checkout/high ×5, actions/missing-workflow-permissions ×6CodeQLhighfixed≈ v0.1.02025-12-05
3 dismissed alerts——false positive: 3——
go-openapi/codegen
6 fixed alerts: CVE-2026-56864, CVE-2026-56865, GO-2026-5932 ×2, GO-2026-6179, GO-2026-6180Trivy, govulncheckunratedfixedv0.0.12026-08-24
go-openapi/codescan
1 fixed alert: CVE-2026-81176Dependabotmediumfixed≈ v0.36.52026-09-25
15 fixed alerts: CVE-2026-47429, CVE-2026-53571, CVE-2026-39365, CVE-2026-53632, GHSA-67mh-4wv8-2f99, CVE-2026-56864 ×4, CVE-2026-56865 ×4, GO-2026-6179, GO-2026-6180Dependabot, Trivy, govulncheckcriticalfixedv0.36.42026-08-21
20 fixed alerts: CVE-2026-25681 ×2, CVE-2026-27136 ×2, CVE-2026-33814 ×2, CVE-2026-39821 ×2, CVE-2026-56852 ×2, CVE-2026-25680 ×4, CVE-2026-42502 ×2, CVE-2026-42506 ×2, CVE-2026-46600 ×2Dependabot, Trivyhighfixedv0.36.02026-07-31
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.34.12026-06-11
1 dismissed alert——false positive: 1——
go-openapi/doc-site
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedno releasesfixed 2026-06-05
go-openapi/errors
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.22.82026-06-02
1 fixed alert: actions/missing-workflow-permissionsCodeQLmediumfixedv0.22.52025-12-06
2 dismissed alerts——false positive: 2——
go-openapi/go-yaml
153 fixed alerts: CVE-2024-45337 ×3, CVE-2026-39830 ×3, CVE-2026-39831 ×3, CVE-2026-39832 ×3, CVE-2026-39833 ×3, CVE-2026-39834 ×3, CVE-2026-42508 ×3, CVE-2026-46595 ×3, CVE-2024-45338, CVE-2025-22869 ×3, CVE-2025-47913, CVE-2026-13149 ×2, CVE-2026-14257 ×2, CVE-2026-25681, CVE-2026-26996 ×2, CVE-2026-27136, CVE-2026-27606, CVE-2026-27903 ×2, CVE-2026-27904 ×2, CVE-2026-32141, CVE-2026-33228, CVE-2026-33671 ×2, CVE-2026-33814, CVE-2026-39363, CVE-2026-39821, CVE-2026-39828 ×3, CVE-2026-39829 ×3, CVE-2026-39835 ×3, CVE-2026-45623, CVE-2026-46597 ×3, CVE-2026-46599 ×3, CVE-2026-46600, CVE-2026-46602, CVE-2026-53571, CVE-2026-56852 ×2, CVE-2026-59869, CVE-2026-67213, CVE-2026-67214, CVE-2026-69152 ×2, CVE-2026-73646, GHSA-5p4m-2wfm-xmqj, go/incorrect-integer-conversion ×12, CVE-2025-22870 ×3, CVE-2025-22872 ×3, CVE-2025-30208, CVE-2025-31125, CVE-2025-31486, CVE-2025-32395, CVE-2025-46565, CVE-2025-47911, CVE-2025-47914 ×3, CVE-2025-58181 ×3, CVE-2025-58190, CVE-2025-62522, CVE-2025-64718, CVE-2025-69873, CVE-2026-25680 ×3, CVE-2026-33532 ×3, CVE-2026-33672 ×2, CVE-2026-33750 ×2, CVE-2026-33809 ×3, CVE-2026-33812, CVE-2026-33813, CVE-2026-39365, CVE-2026-39827 ×3, CVE-2026-41305, CVE-2026-42500, CVE-2026-42502, CVE-2026-42506, CVE-2026-46598 ×3, CVE-2026-46601, CVE-2026-46604, CVE-2026-53550, CVE-2026-53632, CVE-2026-69153, CVE-2023-36308 ×3, CVE-2025-58751, CVE-2025-58752, CVE-2025-5889 ×2, CVE-2026-49356, GHSA-xffm-g5w8-qvg7, CVE-2026-39824, CVE-2026-46603CodeQL, Dependabot, Trivycriticalfixedno releasesfixed 2026-09-14
6 open alerts: 6 code scanning—high 3 medium 2 unrated 1open——
go-openapi/inflect
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.21.62026-06-05
1 dismissed alert——false positive: 1——
go-openapi/jsonpointer
GHSA-cqr7-r6x2-9cqf jsonpointer: Uncaught panic in default `NameProvider` when a struct embeds a pointer or non-struct anonymous field@manqingzhouhighpublished 2026-09-24v1.0.22026-09-24
GHSA-m8w9-vj7g-gxgg jsonpointer: Uncaught `reflect` panic on `Set` with a `nil` value into a struct field or slice element@manqingzhoumediumpublished 2026-09-24v1.0.22026-09-24
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.23.22026-06-28
2 fixed alerts: CVE-2022-3064, CVE-2021-4235Dependabothighfixed≈ v0.22.22025-11-14
go-openapi/jsonreference
GHSA-5x36-4ggc-m9g9 O(n²) removeDefaultPort Enables Single-Request CPU-Exhaustion DoS in go-openapi/jsonreference@manqingzhoulowpublished 2026-09-25v1.0.32026-09-25
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.21.62026-05-31
4 fixed alerts: CVE-2022-3064, CVE-2019-11254, CVE-2021-4235, actions/missing-workflow-permissionsCodeQL, Dependabothighfixedv0.21.42025-12-08
2 dismissed alerts——false positive: 2——
go-openapi/loads
2 fixed alerts: CVE-2026-46600, CVE-2026-56852Trivyunratedfixedv0.24.12026-07-20
17 fixed alerts: GO-2026-4559, GO-2026-4918, GO-2026-5025 ×2, GO-2026-5026 ×2, GO-2026-5027 ×2, GO-2026-5028 ×2, GO-2026-5029 ×2, GO-2026-5030 ×2, GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.23.42026-06-02
1 fixed alert: actions/missing-workflow-permissionsCodeQLmediumfixedv0.23.32026-03-08
2 dismissed alerts——false positive: 2——
go-openapi/runtime
3 fixed alerts: CVE-2026-56852 ×3Trivyunratedfixedv0.32.52026-07-16
9 fixed alerts: GO-2026-5025, GO-2026-5026, GO-2026-5027, GO-2026-5028, GO-2026-5029, GO-2026-5030, GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.32.32026-06-02
8 fixed alerts: GO-2026-4918, GO-2026-4971, GO-2026-4976, GO-2026-4977, GO-2026-4980, GO-2026-4981, GO-2026-4982, GO-2026-4986govulncheckunratedfixedv0.30.02026-05-13
7 fixed alerts: CVE-2026-39883 ×2, private-key ×4, GO-2026-4559Dependabot, Trivy, govulncheckhighfixedv0.29.42026-04-18
3 fixed alerts: go/unsafe-quoting, CVE-2026-24051, actions/missing-workflow-permissionsCodeQL, Dependabotcriticalfixedv0.29.32026-03-08
6 fixed alerts: CVE-2022-27664 ×2, CVE-2022-32149 ×2, CVE-2022-41723 ×2Dependabothighfixed≈ v0.26.22023-12-09
3 dismissed alerts——false positive: 3——
go-openapi/spec
GHSA-gqhc-vf4h-h7hg Server-Side Request Forgery (SSRF) via `$ref` HTTP resolution@RamiAltaicriticalpublished 2026-07-21v0.22.9
go-openapi/validate v0.26.1
2026-07-20
GHSA-pxx3-v77h-v677 Denial of service via exponential $ref expansion ("billion laughs") in ExpandSpec / ExpandSchema@KrisKennawayDDhighpublished 2026-07-21v0.22.72026-07-20
GHSA-c68w-432j-47vw Denial of Service in go-openapi/spec via Unbounded http.Get() in Ref.IsValidURI()@RamiAltaimediumpublished 2026-07-21v0.22.7
go-openapi/validate v0.26.1
2026-07-20
GHSA-rfvj-p9c8-c4ch Arbitrary Local File Read via `file://` `$ref` (Path Traversal)@RamiAltaihighpublished 2026-07-21v0.22.72026-07-20
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.22.52026-06-02
1 fixed alert: actions/missing-workflow-permissionsCodeQLmediumfixedv0.22.22025-12-08
2 dismissed alerts——false positive: 2——
go-openapi/strfmt
2 fixed alerts: CVE-2026-56855, CVE-2026-78662Trivyunratedfixedv0.27.22026-09-03
3 fixed alerts: CVE-2026-56855, CVE-2026-78662, GO-2026-5932Trivyunratedfixedv0.27.12026-09-03
9 fixed alerts: GO-2026-5025, GO-2026-5026, GO-2026-5027, GO-2026-5028, GO-2026-5029, GO-2026-5030, GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.26.32026-05-31
3 fixed alerts: CVE-2026-41889, GO-2026-4559 ×2Dependabot, govulnchecklowfixedv0.26.22026-04-29
6 fixed alerts: CVE-2025-22870, CVE-2025-22872, GHSA-fv92-fjc5-jj9h, actions/missing-workflow-permissions, CVE-2026-26958 ×2CodeQL, Dependabot, Trivymediumfixedv0.26.02026-03-07
3 dismissed alerts——false positive: 3——
go-openapi/swag
GHSA-hwp8-w8pv-xq8f Uncontrolled resource consumption via YAML anchor/alias expansion in YAMLToJSON ("billion laughs") (DoS)@weiz-cnmediumpublished 2026-07-19yamlutils v0.27.12026-07-19
GHSA-xh24-9qpg-8w28 Uncontrolled recursion in ordered JSON marshal/unmarshal causes stack-exhaustion crash (DoS)@weiz-cnhighpublished 2026-07-19jsonutils v0.27.12026-07-19
3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.26.12026-06-07
7 fixed alerts: actions/missing-workflow-permissions ×7CodeQLmediumfixedv0.25.52026-03-02
go-openapi/testify
3 fixed alerts: CVE-2026-56852, CVE-2026-39824 ×2Trivyhighfixedv2.6.12026-08-13
4 fixed alerts: CVE-2026-39824, GO-2026-5037, GO-2026-5038, GO-2026-5039Trivy, govulncheckunratedfixedv2.6.02026-06-25
go-openapi/validate
2 advisories under analysis——triage——
1 fixed alert: CVE-2026-56852Trivyunratedfixedv0.26.12026-07-21
16 fixed alerts: GO-2026-4559, GO-2026-5025 ×2, GO-2026-5026 ×2, GO-2026-5027 ×2, GO-2026-5028 ×2, GO-2026-5029 ×2, GO-2026-5030 ×2, GO-2026-5037, GO-2026-5038, GO-2026-5039govulncheckunratedfixedv0.25.32026-05-31
14 fixed alerts: CVE-2021-33194 ×2, CVE-2022-27664 ×2, CVE-2022-32149 ×2, CVE-2022-41721, CVE-2022-41723 ×2, CVE-2021-31525 ×2, actions/missing-workflow-permissions ×3CodeQL, Dependabothighfixedv0.25.22026-03-08
2 dismissed alerts——false positive: 2——
go-swagger/dockerctl
2 fixed alerts: actions/missing-workflow-permissions ×2CodeQLmediumfixedno releasesfixed 2026-08-12
2 open alerts: 2 code scanning—medium 2open——
go-swagger/examples
11 fixed alerts: CVE-2026-34986, private-key ×4, jwt-token ×3, GO-2026-5037, GO-2026-5038, GO-2026-5039Trivy, govulncheckhighfixedno releasesfixed 2026-06-08
go-swagger/go-swagger
4 fixed alerts: CVE-2026-56855, CVE-2026-78662, GO-2026-6354, GO-2026-6355Trivy, govulncheckmediumfixedv0.36.62026-09-10
4 fixed alerts: GO-2026-5932 ×4Trivy, govulncheckunratedfixedv0.36.52026-08-24
GHSA-x424-rhg7-xx24 go-swagger 生成器 schema property 名注入导致生成模型代码任意代码执行(RCE)@haomoumoulowpublished 2026-08-14v0.36.32026-08-14
GHSA-p7q6-7j2r-cggq go-swagger Response Header Name Injection leading to Arbitrary Code Execution (RCE)@haomoumoucriticalpublished 2026-08-14v0.36.32026-08-14
4 fixed alerts: CVE-2026-56864, CVE-2026-56865, GO-2026-6179, GO-2026-6180Trivy, govulncheckunratedfixedv0.36.32026-08-14
GHSA-8gmg-wf5j-hvf7 RCE via consumes/produces content-type -> unescaped server ConsumersFor/ProducersFor@Gal3m, @mrostamipoorhighpublished 2026-07-22v0.35.32026-07-22
GHSA-gr68-2w3v-34h2 RCE via OpenAPI path -> unescaped client message strings (NewAPIError / Error() / String())@Gal3m, @mrostamipoorcriticalpublished 2026-07-22v0.35.32026-07-22
GHSA-rg22-m539-jwvf Package-init RCE via enum value -> unescaped backtick in func init() raw string@Gal3m, @mrostamipoorcriticalpublished 2026-07-22v0.35.32026-07-22
GHSA-f2g4-8g7f-jmg3 Code Injection via Unsafe OpenAPI Specification Processing@abhayclasherhighpublished 2026-07-21v0.35.22026-07-21
1 fixed alert: CVE-2026-56852Trivyunratedfixedv0.35.12026-07-20
GHSA-x32f-447m-m4f9 Generated Go code injection via unescaped `x-go-custom-tag` values@sondt99criticalpublished 2026-07-21v0.35.02026-06-26
GHSA-2mr7-97cc-77wx Generated Go code injection via unescaped OpenAPI documentation fields in server templates@sondt99criticalpublished 2026-07-21v0.35.02026-06-26
GHSA-hmr9-j4xp-6w23 Arbitrary code execution and token theft in privileged CI context via artifact poisoning — any fork PR exfiltrates the `go-swagger/examples` GitHub App token and the `GITHUB_TOKEN`@EladMeged-Noveemediumpublished 2026-06-07commit 2ca5d34—
17 fixed alerts: CVE-2024-45337 ×2, CVE-2025-22869 ×2, CVE-2025-30204 ×2, go/clear-text-logging, private-key ×2, CVE-2025-22870 ×2, CVE-2025-22872 ×2, CVE-2025-47914 ×2, CVE-2025-58181 ×2CodeQL, Dependabot, Trivycriticalfixedv0.33.22026-03-15
9 fixed alerts: CVE-2024-45337, CVE-2025-22868, CVE-2025-22869, CVE-2025-30204, CVE-2025-11065, CVE-2025-22870, CVE-2025-22872, CVE-2025-27144, GHSA-fv92-fjc5-jj9hDependabotcriticalfixed≈ v0.33.12025-10-07
5 fixed alerts: CVE-2023-39325, CVE-2023-3978, CVE-2023-44487, CVE-2023-45288, CVE-2024-28180Dependabothighfixed≈ v0.31.02024-05-13
2 fixed alerts: CVE-2022-41723 ×2Dependabothighfixed≈ v0.30.52023-06-10
15 dismissed alerts——false positive: 13, won't fix: 2——
2 open alerts: 2 code scanning—unrated 2open——

Fixed in: code scanning alerts show the first release whose tag contains the commit that fixed the alert. ≈ marks a release inferred from dates instead: the first release published after the alert was fixed. This applies to Dependabot alerts, which record no commit, and to code scanning alerts whose fixing commit is unknown or no longer on the default branch (rewritten history).

No advisories or alerts on: go-openapi/conformance-suites, go-openapi/core, go-openapi/gh-actions, go-swagger/go-swagger.github.io, go-swagger/homebrew-go-swagger, go-swagger/scan-repo-boundary.

Alerts from all code scanning tools but Scorecard, plus Dependabot. Last updated: 2026-10-08 12:33 UTC

Current posture regarding CVE publication

We are thoroughly reviewing security advisories that reporters kindly submit to our repos. We try to apply the necessary fixes and to release as promptly as possible.

We publish valid advisories on GitHub’s global database of security advisories: https://github.com/advisories.

For the moment however, we have suspended the next natural step, which is to request a CVE.

We’ll get back to a regular workflow with CVE requests as soon as we’ve stabilized the influx of reports that currently still need a lot of time to triage.