Server-side Request Forgery (SSRF) Affecting github.com/oasdiff/oasdiff/load package, versions >=1.13.2 <1.18.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMOASDIFFOASDIFFLOAD-17893238
  • published8 Jul 2026
  • disclosed7 Jul 2026
  • creditUnknown

Introduced: 7 Jul 2026

CVE-2026-53508  (opens in a new tab)
CWE-693  (opens in a new tab)
CWE-73  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade github.com/oasdiff/oasdiff/load to version 1.18.1 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through loadFromGitRevision. An attacker can force the loader to fetch an internal URL or read a local file by supplying a rev:path OpenAPI source whose schema contains an external $ref, even when the caller set --allow-external-refs=false. This affects users processing untrusted specs from git revisions, including CLI commands and library consumers that rely on IsExternalRefsAllowed = false for safety. The result is SSRF or local file disclosure during spec loading, which can expose internal services or sensitive host files and break the intended restriction on external references.

CVSS Base Scores

version 4.0
version 3.1