Microsoft.OpenApi is vulnerable to Denial of Service (DoS).
63
Medium Risk
Circular OpenAPI schema/reference resolution could previously lead to unbounded recursion (and potential stack overflow / non-termination). The fix adds visited-reference tracking during resolution and throws an error when a cycle is detected, stopping the Denial of Service condition.
If you use Microsoft.OpenApi with a version within the vulnerable ranges to parse/resolve OpenAPI documents that include circular reference structures.
Microsoft.OpenApi is vulnerable to Denial of Service (DoS). in versions 2.0.0 - 2.7.4 and 3.0.0 - 3.5.3.
Upgrade the package to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant