Security Flaw in oasdiff-action GitHub Action Affects OpenAPI Specifications
CVE-2026-53507

8.3HIGH

Key Information:

Vendor

Oasdiff

Vendor
CVE Published:
31 August 2026

What is CVE-2026-53507?

The oasdiff-action, a GitHub Action for detecting breaking changes in OpenAPI specifications, contains a vulnerability that allows malicious actors to exploit external references in OpenAPI specs. Prior to version 0.0.51, the action resolved external $refs automatically, which could lead to Server-Side Request Forgery (SSRF) attacks when processing attacker-controlled pull requests. This vulnerability can expose sensitive data from the runner environment without any interaction, making it crucial for users to upgrade to the patched version to safeguard against unauthorized data access.

Affected Version(s)

oasdiff-action < 0.0.51

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.