Security advisories
Security advisories and code scanning alerts on all go-openapi and go-swagger repositories: reporters, severities and the releases that fixed them, refreshed daily.
Advisories still under analysis (triage or draft) are only counted, not disclosed. We keep as few of them as we can.
Summary
| Repo | Published advisories | Under analysis | Fixed alerts | Fixed, not released | Dismissed alerts | Open alerts |
|---|---|---|---|---|---|---|
| go-openapi | ||||||
| analysis | 0 | — | 11 | — | 20 | 0 |
| ci-workflows | 0 | — | 14 | — | 3 | 0 |
| codegen | 0 | — | 6 | — | — | 0 |
| codescan | 0 | — | 39 | — | 1 | 0 |
| doc-site | 0 | — | 3 | — | — | 0 |
| errors | 0 | — | 4 | — | 2 | 0 |
| go-yaml | 0 | — | 153 | — | — | ⚠️ 6 |
| inflect | 0 | — | 3 | — | 1 | 0 |
| jsonpointer | 2 | — | 5 | — | — | 0 |
| jsonreference | 1 | — | 7 | — | 2 | 0 |
| loads | 0 | — | 20 | — | 2 | 0 |
| runtime | 0 | — | 36 | — | 3 | 0 |
| spec | 4 | — | 4 | — | 2 | 0 |
| strfmt | 0 | — | 23 | — | 3 | 0 |
| swag | 2 | — | 10 | — | — | 0 |
| testify | 0 | — | 7 | — | — | 0 |
| validate | 0 | ⚠️ 2 | 31 | — | 2 | 0 |
| go-openapi total | 9 | 2 | 376 | 0 | 41 | 6 |
| go-swagger | ||||||
| dockerctl | 0 | — | 2 | — | — | ⚠️ 2 |
| examples | 0 | — | 11 | — | — | 0 |
| go-swagger | 9 | — | 46 | — | 15 | ⚠️ 2 |
| go-swagger total | 9 | 0 | 59 | 0 | 15 | 4 |
| Grand total | 18 | 2 | 435 | 0 | 56 | 10 |
Detailed report
| Item | Reporter / source | Severity | Status | Fixed in | Date |
|---|---|---|---|---|---|
| go-openapi/analysis | |||||
| 9 fixed alerts: GO-2026-5025, GO-2026-5026, GO-2026-5027, GO-2026-5028, GO-2026-5029, GO-2026-5030, GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.25.2 | 2026-06-02 |
| 1 fixed alert: GO-2026-4559 | govulncheck | unrated | fixed | v0.25.0 | 2026-03-17 |
| 1 fixed alert: actions/missing-workflow-permissions | CodeQL | medium | fixed | v0.24.2 | 2025-12-15 |
| 20 dismissed alerts | — | — | false positive: 20 | — | — |
| go-openapi/ci-workflows | |||||
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.3.5 | 2026-06-07 |
| 11 fixed alerts: actions/untrusted-checkout/high ×5, actions/missing-workflow-permissions ×6 | CodeQL | high | fixed | ≈ v0.1.0 | 2025-12-05 |
| 3 dismissed alerts | — | — | false positive: 3 | — | — |
| go-openapi/codegen | |||||
| 6 fixed alerts: CVE-2026-56864, CVE-2026-56865, GO-2026-5932 ×2, GO-2026-6179, GO-2026-6180 | Trivy, govulncheck | unrated | fixed | v0.0.1 | 2026-08-24 |
| go-openapi/codescan | |||||
| 1 fixed alert: CVE-2026-81176 | Dependabot | medium | fixed | ≈ v0.36.5 | 2026-09-25 |
| 15 fixed alerts: CVE-2026-47429, CVE-2026-53571, CVE-2026-39365, CVE-2026-53632, GHSA-67mh-4wv8-2f99, CVE-2026-56864 ×4, CVE-2026-56865 ×4, GO-2026-6179, GO-2026-6180 | Dependabot, Trivy, govulncheck | critical | fixed | v0.36.4 | 2026-08-21 |
| 20 fixed alerts: CVE-2026-25681 ×2, CVE-2026-27136 ×2, CVE-2026-33814 ×2, CVE-2026-39821 ×2, CVE-2026-56852 ×2, CVE-2026-25680 ×4, CVE-2026-42502 ×2, CVE-2026-42506 ×2, CVE-2026-46600 ×2 | Dependabot, Trivy | high | fixed | v0.36.0 | 2026-07-31 |
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.34.1 | 2026-06-11 |
| 1 dismissed alert | — | — | false positive: 1 | — | — |
| go-openapi/doc-site | |||||
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | no releases | fixed 2026-06-05 |
| go-openapi/errors | |||||
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.22.8 | 2026-06-02 |
| 1 fixed alert: actions/missing-workflow-permissions | CodeQL | medium | fixed | v0.22.5 | 2025-12-06 |
| 2 dismissed alerts | — | — | false positive: 2 | — | — |
| go-openapi/go-yaml | |||||
| 153 fixed alerts: CVE-2024-45337 ×3, CVE-2026-39830 ×3, CVE-2026-39831 ×3, CVE-2026-39832 ×3, CVE-2026-39833 ×3, CVE-2026-39834 ×3, CVE-2026-42508 ×3, CVE-2026-46595 ×3, CVE-2024-45338, CVE-2025-22869 ×3, CVE-2025-47913, CVE-2026-13149 ×2, CVE-2026-14257 ×2, CVE-2026-25681, CVE-2026-26996 ×2, CVE-2026-27136, CVE-2026-27606, CVE-2026-27903 ×2, CVE-2026-27904 ×2, CVE-2026-32141, CVE-2026-33228, CVE-2026-33671 ×2, CVE-2026-33814, CVE-2026-39363, CVE-2026-39821, CVE-2026-39828 ×3, CVE-2026-39829 ×3, CVE-2026-39835 ×3, CVE-2026-45623, CVE-2026-46597 ×3, CVE-2026-46599 ×3, CVE-2026-46600, CVE-2026-46602, CVE-2026-53571, CVE-2026-56852 ×2, CVE-2026-59869, CVE-2026-67213, CVE-2026-67214, CVE-2026-69152 ×2, CVE-2026-73646, GHSA-5p4m-2wfm-xmqj, go/incorrect-integer-conversion ×12, CVE-2025-22870 ×3, CVE-2025-22872 ×3, CVE-2025-30208, CVE-2025-31125, CVE-2025-31486, CVE-2025-32395, CVE-2025-46565, CVE-2025-47911, CVE-2025-47914 ×3, CVE-2025-58181 ×3, CVE-2025-58190, CVE-2025-62522, CVE-2025-64718, CVE-2025-69873, CVE-2026-25680 ×3, CVE-2026-33532 ×3, CVE-2026-33672 ×2, CVE-2026-33750 ×2, CVE-2026-33809 ×3, CVE-2026-33812, CVE-2026-33813, CVE-2026-39365, CVE-2026-39827 ×3, CVE-2026-41305, CVE-2026-42500, CVE-2026-42502, CVE-2026-42506, CVE-2026-46598 ×3, CVE-2026-46601, CVE-2026-46604, CVE-2026-53550, CVE-2026-53632, CVE-2026-69153, CVE-2023-36308 ×3, CVE-2025-58751, CVE-2025-58752, CVE-2025-5889 ×2, CVE-2026-49356, GHSA-xffm-g5w8-qvg7, CVE-2026-39824, CVE-2026-46603 | CodeQL, Dependabot, Trivy | critical | fixed | no releases | fixed 2026-09-14 |
| 6 open alerts: 6 code scanning | — | high 3 medium 2 unrated 1 | open | — | — |
| go-openapi/inflect | |||||
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.21.6 | 2026-06-05 |
| 1 dismissed alert | — | — | false positive: 1 | — | — |
| go-openapi/jsonpointer | |||||
| GHSA-cqr7-r6x2-9cqf jsonpointer: Uncaught panic in default `NameProvider` when a struct embeds a pointer or non-struct anonymous field | @manqingzhou | high | published 2026-09-24 | v1.0.2 | 2026-09-24 |
| GHSA-m8w9-vj7g-gxgg jsonpointer: Uncaught `reflect` panic on `Set` with a `nil` value into a struct field or slice element | @manqingzhou | medium | published 2026-09-24 | v1.0.2 | 2026-09-24 |
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.23.2 | 2026-06-28 |
| 2 fixed alerts: CVE-2022-3064, CVE-2021-4235 | Dependabot | high | fixed | ≈ v0.22.2 | 2025-11-14 |
| go-openapi/jsonreference | |||||
| GHSA-5x36-4ggc-m9g9 O(n²) removeDefaultPort Enables Single-Request CPU-Exhaustion DoS in go-openapi/jsonreference | @manqingzhou | low | published 2026-09-25 | v1.0.3 | 2026-09-25 |
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.21.6 | 2026-05-31 |
| 4 fixed alerts: CVE-2022-3064, CVE-2019-11254, CVE-2021-4235, actions/missing-workflow-permissions | CodeQL, Dependabot | high | fixed | v0.21.4 | 2025-12-08 |
| 2 dismissed alerts | — | — | false positive: 2 | — | — |
| go-openapi/loads | |||||
| 2 fixed alerts: CVE-2026-46600, CVE-2026-56852 | Trivy | unrated | fixed | v0.24.1 | 2026-07-20 |
| 17 fixed alerts: GO-2026-4559, GO-2026-4918, GO-2026-5025 ×2, GO-2026-5026 ×2, GO-2026-5027 ×2, GO-2026-5028 ×2, GO-2026-5029 ×2, GO-2026-5030 ×2, GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.23.4 | 2026-06-02 |
| 1 fixed alert: actions/missing-workflow-permissions | CodeQL | medium | fixed | v0.23.3 | 2026-03-08 |
| 2 dismissed alerts | — | — | false positive: 2 | — | — |
| go-openapi/runtime | |||||
| 3 fixed alerts: CVE-2026-56852 ×3 | Trivy | unrated | fixed | v0.32.5 | 2026-07-16 |
| 9 fixed alerts: GO-2026-5025, GO-2026-5026, GO-2026-5027, GO-2026-5028, GO-2026-5029, GO-2026-5030, GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.32.3 | 2026-06-02 |
| 8 fixed alerts: GO-2026-4918, GO-2026-4971, GO-2026-4976, GO-2026-4977, GO-2026-4980, GO-2026-4981, GO-2026-4982, GO-2026-4986 | govulncheck | unrated | fixed | v0.30.0 | 2026-05-13 |
| 7 fixed alerts: CVE-2026-39883 ×2, private-key ×4, GO-2026-4559 | Dependabot, Trivy, govulncheck | high | fixed | v0.29.4 | 2026-04-18 |
| 3 fixed alerts: go/unsafe-quoting, CVE-2026-24051, actions/missing-workflow-permissions | CodeQL, Dependabot | critical | fixed | v0.29.3 | 2026-03-08 |
| 6 fixed alerts: CVE-2022-27664 ×2, CVE-2022-32149 ×2, CVE-2022-41723 ×2 | Dependabot | high | fixed | ≈ v0.26.2 | 2023-12-09 |
| 3 dismissed alerts | — | — | false positive: 3 | — | — |
| go-openapi/spec | |||||
| GHSA-gqhc-vf4h-h7hg Server-Side Request Forgery (SSRF) via `$ref` HTTP resolution | @RamiAltai | critical | published 2026-07-21 | v0.22.9 go-openapi/validate v0.26.1 | 2026-07-20 |
| GHSA-pxx3-v77h-v677 Denial of service via exponential $ref expansion ("billion laughs") in ExpandSpec / ExpandSchema | @KrisKennawayDD | high | published 2026-07-21 | v0.22.7 | 2026-07-20 |
| GHSA-c68w-432j-47vw Denial of Service in go-openapi/spec via Unbounded http.Get() in Ref.IsValidURI() | @RamiAltai | medium | published 2026-07-21 | v0.22.7 go-openapi/validate v0.26.1 | 2026-07-20 |
| GHSA-rfvj-p9c8-c4ch Arbitrary Local File Read via `file://` `$ref` (Path Traversal) | @RamiAltai | high | published 2026-07-21 | v0.22.7 | 2026-07-20 |
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.22.5 | 2026-06-02 |
| 1 fixed alert: actions/missing-workflow-permissions | CodeQL | medium | fixed | v0.22.2 | 2025-12-08 |
| 2 dismissed alerts | — | — | false positive: 2 | — | — |
| go-openapi/strfmt | |||||
| 2 fixed alerts: CVE-2026-56855, CVE-2026-78662 | Trivy | unrated | fixed | v0.27.2 | 2026-09-03 |
| 3 fixed alerts: CVE-2026-56855, CVE-2026-78662, GO-2026-5932 | Trivy | unrated | fixed | v0.27.1 | 2026-09-03 |
| 9 fixed alerts: GO-2026-5025, GO-2026-5026, GO-2026-5027, GO-2026-5028, GO-2026-5029, GO-2026-5030, GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.26.3 | 2026-05-31 |
| 3 fixed alerts: CVE-2026-41889, GO-2026-4559 ×2 | Dependabot, govulncheck | low | fixed | v0.26.2 | 2026-04-29 |
| 6 fixed alerts: CVE-2025-22870, CVE-2025-22872, GHSA-fv92-fjc5-jj9h, actions/missing-workflow-permissions, CVE-2026-26958 ×2 | CodeQL, Dependabot, Trivy | medium | fixed | v0.26.0 | 2026-03-07 |
| 3 dismissed alerts | — | — | false positive: 3 | — | — |
| go-openapi/swag | |||||
| GHSA-hwp8-w8pv-xq8f Uncontrolled resource consumption via YAML anchor/alias expansion in YAMLToJSON ("billion laughs") (DoS) | @weiz-cn | medium | published 2026-07-19 | yamlutils v0.27.1 | 2026-07-19 |
| GHSA-xh24-9qpg-8w28 Uncontrolled recursion in ordered JSON marshal/unmarshal causes stack-exhaustion crash (DoS) | @weiz-cn | high | published 2026-07-19 | jsonutils v0.27.1 | 2026-07-19 |
| 3 fixed alerts: GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.26.1 | 2026-06-07 |
| 7 fixed alerts: actions/missing-workflow-permissions ×7 | CodeQL | medium | fixed | v0.25.5 | 2026-03-02 |
| go-openapi/testify | |||||
| 3 fixed alerts: CVE-2026-56852, CVE-2026-39824 ×2 | Trivy | high | fixed | v2.6.1 | 2026-08-13 |
| 4 fixed alerts: CVE-2026-39824, GO-2026-5037, GO-2026-5038, GO-2026-5039 | Trivy, govulncheck | unrated | fixed | v2.6.0 | 2026-06-25 |
| go-openapi/validate | |||||
| 2 advisories under analysis | — | — | triage | — | — |
| 1 fixed alert: CVE-2026-56852 | Trivy | unrated | fixed | v0.26.1 | 2026-07-21 |
| 16 fixed alerts: GO-2026-4559, GO-2026-5025 ×2, GO-2026-5026 ×2, GO-2026-5027 ×2, GO-2026-5028 ×2, GO-2026-5029 ×2, GO-2026-5030 ×2, GO-2026-5037, GO-2026-5038, GO-2026-5039 | govulncheck | unrated | fixed | v0.25.3 | 2026-05-31 |
| 14 fixed alerts: CVE-2021-33194 ×2, CVE-2022-27664 ×2, CVE-2022-32149 ×2, CVE-2022-41721, CVE-2022-41723 ×2, CVE-2021-31525 ×2, actions/missing-workflow-permissions ×3 | CodeQL, Dependabot | high | fixed | v0.25.2 | 2026-03-08 |
| 2 dismissed alerts | — | — | false positive: 2 | — | — |
| go-swagger/dockerctl | |||||
| 2 fixed alerts: actions/missing-workflow-permissions ×2 | CodeQL | medium | fixed | no releases | fixed 2026-08-12 |
| 2 open alerts: 2 code scanning | — | medium 2 | open | — | — |
| go-swagger/examples | |||||
| 11 fixed alerts: CVE-2026-34986, private-key ×4, jwt-token ×3, GO-2026-5037, GO-2026-5038, GO-2026-5039 | Trivy, govulncheck | high | fixed | no releases | fixed 2026-06-08 |
| go-swagger/go-swagger | |||||
| 4 fixed alerts: CVE-2026-56855, CVE-2026-78662, GO-2026-6354, GO-2026-6355 | Trivy, govulncheck | medium | fixed | v0.36.6 | 2026-09-10 |
| 4 fixed alerts: GO-2026-5932 ×4 | Trivy, govulncheck | unrated | fixed | v0.36.5 | 2026-08-24 |
| GHSA-x424-rhg7-xx24 go-swagger 生成器 schema property 名注入导致生成模型代码任意代码执行(RCE) | @haomoumou | low | published 2026-08-14 | v0.36.3 | 2026-08-14 |
| GHSA-p7q6-7j2r-cggq go-swagger Response Header Name Injection leading to Arbitrary Code Execution (RCE) | @haomoumou | critical | published 2026-08-14 | v0.36.3 | 2026-08-14 |
| 4 fixed alerts: CVE-2026-56864, CVE-2026-56865, GO-2026-6179, GO-2026-6180 | Trivy, govulncheck | unrated | fixed | v0.36.3 | 2026-08-14 |
| GHSA-8gmg-wf5j-hvf7 RCE via consumes/produces content-type -> unescaped server ConsumersFor/ProducersFor | @Gal3m, @mrostamipoor | high | published 2026-07-22 | v0.35.3 | 2026-07-22 |
| GHSA-gr68-2w3v-34h2 RCE via OpenAPI path -> unescaped client message strings (NewAPIError / Error() / String()) | @Gal3m, @mrostamipoor | critical | published 2026-07-22 | v0.35.3 | 2026-07-22 |
| GHSA-rg22-m539-jwvf Package-init RCE via enum value -> unescaped backtick in func init() raw string | @Gal3m, @mrostamipoor | critical | published 2026-07-22 | v0.35.3 | 2026-07-22 |
| GHSA-f2g4-8g7f-jmg3 Code Injection via Unsafe OpenAPI Specification Processing | @abhayclasher | high | published 2026-07-21 | v0.35.2 | 2026-07-21 |
| 1 fixed alert: CVE-2026-56852 | Trivy | unrated | fixed | v0.35.1 | 2026-07-20 |
| GHSA-x32f-447m-m4f9 Generated Go code injection via unescaped `x-go-custom-tag` values | @sondt99 | critical | published 2026-07-21 | v0.35.0 | 2026-06-26 |
| GHSA-2mr7-97cc-77wx Generated Go code injection via unescaped OpenAPI documentation fields in server templates | @sondt99 | critical | published 2026-07-21 | v0.35.0 | 2026-06-26 |
| GHSA-hmr9-j4xp-6w23 Arbitrary code execution and token theft in privileged CI context via artifact poisoning — any fork PR exfiltrates the `go-swagger/examples` GitHub App token and the `GITHUB_TOKEN` | @EladMeged-Novee | medium | published 2026-06-07 | commit 2ca5d34 | — |
| 17 fixed alerts: CVE-2024-45337 ×2, CVE-2025-22869 ×2, CVE-2025-30204 ×2, go/clear-text-logging, private-key ×2, CVE-2025-22870 ×2, CVE-2025-22872 ×2, CVE-2025-47914 ×2, CVE-2025-58181 ×2 | CodeQL, Dependabot, Trivy | critical | fixed | v0.33.2 | 2026-03-15 |
| 9 fixed alerts: CVE-2024-45337, CVE-2025-22868, CVE-2025-22869, CVE-2025-30204, CVE-2025-11065, CVE-2025-22870, CVE-2025-22872, CVE-2025-27144, GHSA-fv92-fjc5-jj9h | Dependabot | critical | fixed | ≈ v0.33.1 | 2025-10-07 |
| 5 fixed alerts: CVE-2023-39325, CVE-2023-3978, CVE-2023-44487, CVE-2023-45288, CVE-2024-28180 | Dependabot | high | fixed | ≈ v0.31.0 | 2024-05-13 |
| 2 fixed alerts: CVE-2022-41723 ×2 | Dependabot | high | fixed | ≈ v0.30.5 | 2023-06-10 |
| 15 dismissed alerts | — | — | false positive: 13, won't fix: 2 | — | — |
| 2 open alerts: 2 code scanning | — | unrated 2 | open | — | — |
Fixed in: code scanning alerts show the first release whose tag contains the commit that fixed the alert. ≈ marks a release inferred from dates instead: the first release published after the alert was fixed. This applies to Dependabot alerts, which record no commit, and to code scanning alerts whose fixing commit is unknown or no longer on the default branch (rewritten history).
No advisories or alerts on: go-openapi/conformance-suites, go-openapi/core, go-openapi/gh-actions, go-swagger/go-swagger.github.io, go-swagger/homebrew-go-swagger, go-swagger/scan-repo-boundary.
Alerts from all code scanning tools but Scorecard, plus Dependabot. Last updated: 2026-10-08 12:33 UTC
Current posture regarding CVE publication
We are thoroughly reviewing security advisories that reporters kindly submit to our repos. We try to apply the necessary fixes and to release as promptly as possible.
We publish valid advisories on GitHub’s global database of security advisories: https://github.com/advisories.
For the moment however, we have suspended the next natural step, which is to request a CVE.
We’ll get back to a regular workflow with CVE requests as soon as we’ve stabilized the influx of reports that currently still need a lot of time to triage.