VDB

CVE-2026-73501

CVE-2026-73501 PUBLISHED CVSS 9.1 CRITICAL

Reported by GitHub_M · Published August 12, 2026

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.

Risk Scores

CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
getkinkin-openapi< 0.144.0
getkinkin-openapi< 0.144.0, < 0.144.0

Timeline

  • Aug 12, 2026 CVE Published
  • Aug 13, 2026 Coalition ESS Score
  • Aug 13, 2026 CVE Updated
  • Aug 15, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 4, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›