CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105796

HIGHCVSS 8.8NVD feed

Published 6 October 2026 · tracked since 7 October 2026

Description

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outsi

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105796 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105796

HIGHCVSS 8.8NVD feed

Published 6 October 2026 · tracked since 7 October 2026

Description

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outsi

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]