Known Vulnerabilities for Kin-openapi by Getkin
Listed below are 10 of the newest known vulnerabilities associated with "Kin-openapi" by "Getkin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-101059 json | utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to ... | Not Provided | 2026-09-27 | 2026-09-28 |
| CVE-2026-101058 json | python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual po... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-100680 json | Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, a... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-96759 json | orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options ... | Not Provided | 2026-09-23 | 2026-09-29 |
| CVE-2026-96758 json | orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape mult... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-96757 json | orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literal... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-96756 json | orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-96755 json | orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts Open... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-96754 json | orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI... | Not Provided | 2026-09-23 | 2026-09-29 |
| CVE-2026-94492 json | A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8clou... | Not Provided | 2026-09-22 | 2026-09-22 |