{"id":"CVE-2026-53508","summary":"oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)","details":"oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from a git revision (the rev:path form, e.g. main:openapi.yaml). External $refs were resolved on that load path even when external refs were explicitly disabled, so the mitigation silently did not apply there. This issue has been patched in version 1.18.1.","aliases":["GHSA-2jcc-mxv7-p3f9","GO-2026-5937"],"modified":"2026-09-02T03:47:19.399837651Z","published":"2026-08-31T18:52:12.213Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"cwe_ids":["CWE-693","CWE-73","CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53508.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53508.json"},{"type":"ADVISORY","url":"https://github.com/oasdiff/oasdiff/security/advisories/GHSA-2jcc-mxv7-p3f9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53508"},{"type":"FIX","url":"https://github.com/oasdiff/oasdiff/pull/832"},{"type":"FIX","url":"https://github.com/oasdiff/oasdiff/pull/974"},{"type":"FIX","url":"https://github.com/oasdiff/oasdiff/pull/975"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oasdiff/oasdiff","events":[{"introduced":"d886cb40c4fe95fa69ca7029a88ac7fcf7690a6e"},{"fixed":"e84c5ad34934e3008efca2fc0f3aaed94855b66a"}],"database_specific":{"extracted_events":[{"introduced":"1.13.2"},{"fixed":"1.18.1"},{"fixed":"1.18.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v1.18.0","v1.17.0","v1.16.0","v1.15.3","v1.15.2","v1.15.1","v1.15.0","v1.14.0","v1.13.5","v1.13.4","v1.13.3","v1.13.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53508.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}