CVE-2026-49451

Source
https://cve.org/CVERecord?id=CVE-2026-49451
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-49451.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-49451
Aliases
Published
2026-06-30T16:01:00.819Z
Modified
2026-07-11T03:54:57.200958447Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
Details

The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From 2.0.0-preview11 until 2.7.5 and 3.5.4, a small OpenAPI document containing a circular schema reference can cause process termination through stack overflow in Microsoft.OpenApi. The issue affects OpenAPI document parsing through public OpenAPI.NET reader APIs and has been confirmed across both JSON and YAML reader paths. This vulnerability is fixed in 2.7.5 and 3.5.4.

Database specific
{
    "cwe_ids": [
        "CWE-674"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49451.json"
}
References

Affected packages

Git / github.com/microsoft/openapi.net

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/openapi.net
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.0.0-preview11"
        },
        {
            "fixed": "2.7.5"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.5.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.0-preview
1.3.1
1.3.1-preview
1.3.2
1.4.0
1.4.0-preview1
1.4.0-preview2
1.4.0-preview3
1.4.1
1.4.2
1.4.3
1.4.4
1.4.4-preview1
1.4.5
1.5.0
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.13
1.6.14
1.6.15
1.6.16
1.6.17
1.6.18
1.6.19
1.6.2
1.6.20
1.6.21
1.6.22
1.6.3
1.6.4
1.6.4-preview1
1.6.4-preview2
1.6.4-preview3
1.6.4-preview4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
2.*
2.0.0-preview1
2.0.0-preview2
2.0.0-preview3
2.0.0-preview4
2.0.0-preview5
v1.*
v1.0.0
v1.0.0-beta008
v1.0.0-beta009
v1.0.0-beta010
v1.0.0-beta011
v1.0.0-beta012
v1.0.0-beta013
v1.0.0-beta014
v1.0.0-beta016
v1.0.0-beta017
v1.0.1
v1.1.3
v2.*
v2.0.0
v2.0.0-preview.11
v2.0.0-preview.12
v2.0.0-preview.13
v2.0.0-preview.14
v2.0.0-preview.15
v2.0.0-preview.16
v2.0.0-preview.17
v2.0.0-preview.18
v2.0.0-preview.19
v2.0.0-preview.20
v2.0.0-preview.21
v2.0.0-preview.22
v2.0.0-preview.23
v2.0.0-preview.24
v2.0.0-preview.25
v2.0.0-preview.26
v2.0.0-preview.27
v2.0.0-preview.28
v2.0.0-preview.29
v2.0.0-preview.30
v2.0.0-preview.31
v2.0.0-preview10
v2.0.0-preview7
v2.0.0-preview8
v2.0.0-preview9
v2.0.1
v2.1.0
v2.2.0
v2.3.0
v2.3.1
v2.3.10
v2.3.11
v2.3.12
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.2.0
v3.3.0
v3.3.1
v3.4.0
v3.5.0
v3.5.1
v3.5.2
v3.5.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-49451.json"