Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-53508
Published:July 08, 2026
Updated:August 02, 2026
Summary From v1.13.2 through v1.18.0, oasdiff did not enforce "--allow-external-refs=false" (library: "openapi3.Loader.IsExternalRefsAllowed = false") when loading a spec from a git revision (the "rev:path" form, e.g. "main:openapi.yaml"). External "$ref"s were resolved on that load path even when external refs were explicitly disabled, so the mitigation silently did not apply there. Impact A caller who set "--allow-external-refs=false" specifically to safely process untrusted specs remained exposed — on the git-revision load path only — to: - SSRF via "$ref: "http://<internal-host>/…"", and - Local file reads via "$ref: "/path"" or "file://". Affected callers: - CLI: "oasdiff diff main:openapi.yaml HEAD:openapi.yaml --allow-external-refs=false" (and "breaking" / "changelog" / "summary", and the "git-diff-driver") run over untrusted spec content. - Go library consumers of "github.com/oasdiff/oasdiff/load" that set "IsExternalRefsAllowed = false" and load from a git-revision source via "load.NewSpecInfo". The file and URL load paths correctly enforced the setting; only the git-revision path was affected. Callers that left external refs at the default ("true") are not in scope for this advisory. Patches v1.18.1 enforces the external-refs policy on the git-revision path (so "--allow-external-refs=false" now blocks external "$ref"s there) and returns a dedicated exit code ("123") when an external "$ref" is refused. Workarounds - Upgrade to v1.18.1, or - Avoid the git-revision input form when processing untrusted specs with external refs disabled. Notes - Introduced in v1.13.2 (#832, which added "$ref"-chain resolution on the git-revision path); fixed in v1.18.1 (#974, #975). - The permissive default ("allow-external-refs: true") and its zero-interaction exposure in CI via the GitHub Action is tracked separately in GHSA-fhj3-7267-7vv5 (oasdiff-action).
Affected Packages
github.com/oasdiff/oasdiff (GO):
Affected version(s) >=v1.13.2 <v1.18.1
Fix Suggestion:
Update to version v1.18.1
Do you need more information?
Contact Us
CVSS v4
Base Score:
6
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
6.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
Weakness Type (CWE)
External Control of File Name or Path
Server-Side Request Forgery (SSRF)
Protection Mechanism Failure