CVE-2026-73501
Reported by GitHub_M · Published August 12, 2026
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| getkin | kin-openapi | < 0.144.0 |
| getkin | kin-openapi | < 0.144.0, < 0.144.0 |
Timeline
- Aug 12, 2026 CVE Published
- Aug 13, 2026 Coalition ESS Score
- Aug 13, 2026 CVE Updated
- Aug 15, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score