- Sources: advisory GHSA-jpcw-4wr7-c3vq, kin-openapi v0.145.0 release
- Summary: An advisory describes a NULL-pointer dereference in
openapi3filter.ValidateRequest, the standard request-validation middleware for Go services built on kin-openapi. When no custom ParamDecoder is configured, defaultContentParameterDecoder guards param.Content being nil, len(content) not equal to 1, and the media type object being nil, but never guards mt.Schema being nil, so it dereferences a missing schema at openapi3filter/req_resp_decoder.go around line 197. A parameter declared with content rather than schema, whose media type object carries no schema, is legal under both OpenAPI 3.0.x and 3.1.x and is accepted by kin-openapi's own doc.Validate(), so the sink is reachable from a conforming document. Security is validated before parameters, but the panic needs no credentials whenever the operation declares no security requirement or no AuthenticationFunc is wired, and that function is opt-in. Affected versions are 0.143.0 and below, with the code introduced in v0.2.0, and the advisory names 0.144.0 as the fix. The second source is the v0.145.0 release tag, the current release read at this run. The advisory carries no CVE identifier. - Why it matters: Impact runs from a per-request abort with unbounded panic-log growth to a full remote process crash depending on how the library is wired into the server, and one unauthenticated HTTP request reaches it.
- Follow-up: Watch for a CVE assignment and for whether Go frameworks that vendor kin-openapi pick up 0.144.0 or later.
send feedback on this story