THREAT OPS › Threat News › [GHSA] GHSA-xhj3-7xw9-vr34 (high) — kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
[GHSA] GHSA-xhj3-7xw9-vr34 (high) — kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
GHSA-xhj3-7xw9-vr34 Severity: high CVE: CVE-2026-77354
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
### Summary
An uncontrolled resource consumption vulnerability in `openapi3filter` lets any unauthenticated client force multi-gigabyte heap allocation with a single, tiny HTTP request. When a spec declares a `deepObject`-style query para
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 78bb273e5892da3b0c8fc31857499449adfaba6csha1
- 1d0a337c9b1570fab283be8a04c8af6e43b9a22csha1
- CVE-2026-77354cve
Original source: https://github.com/advisories/GHSA-xhj3-7xw9-vr34