Browse all 2 CVE security advisories affecting oasdiff. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-53507 | oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runs — oasdiff-action CWE-200 | 8.3 | High | 2026-08-31 |
| CVE-2026-53508 | oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) — oasdiff CWE-73 | 6.0 | Medium | 2026-08-31 |
This page lists every published CVE security advisory associated with oasdiff. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.