Oapi-Codegen · Vulnerability Disclosure

Oapi Codegen Vulnerability Disclosure

Vulnerability disclosure

Oapi-Codegen publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

Code GenerationDeveloper ToolsGoOpenAPISDKTooling
Program:

Disclosure Policy

Policy

Security Contact

Contact
{"channel" => "github-security-advisories", "note" => "Coordinated disclosure via the GitHub security advisories page for the affected repository. Public issues, discussions, and pull requests are explicitly not an acceptable reporting channel.", "url" => "https://github.com/oapi-codegen/oapi-codegen/security/advisories/"}

Source

Vulnerability Disclosure

oapi-codegen-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-06'
method: searched
probe: true
source: https://github.com/oapi-codegen/.github/blob/main/SECURITY.md
scope: >-
  oapi-codegen has no hosted surface of its own — it is distributed as Go modules
  and lives entirely in the oapi-codegen GitHub organisation. Its disclosure
  programme is therefore an org-level SECURITY.md plus GitHub Security Advisories,
  not a /.well-known/security.txt on a company domain.
policy:
  - https://github.com/oapi-codegen/.github/blob/main/SECURITY.md
contact:
  - channel: github-security-advisories
    url: https://github.com/oapi-codegen/oapi-codegen/security/advisories/
    note: >-
      Coordinated disclosure via the GitHub security advisories page for the
      affected repository. Public issues, discussions, and pull requests are
      explicitly not an acceptable reporting channel.
model: coordinated-disclosure
bug_bounty: null
supported_versions: latest minor release only (backports considered by severity)
dependency_policy:
  summary: >-
    Dependency CVEs are patched when exploitable under static analysis via
    govulncheck, when a fix requires a code change plus version bump, or during
    routine dependency hygiene. Consumers may override dependency versions in their
    own go.mod ahead of an upstream release.
  tool: https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck
advisories_published:
  registry: https://github.com/oapi-codegen/oapi-codegen/security/advisories
  recent:
    - id: GHSA-9c2f-gr95-7wqw
      severity: medium
      published: '2026-07-21'
      summary: OpenAPI x-go-type-import generated Go code injection
    - id: GHSA-jwgf-6xff-4hvp
      severity: medium
      published: '2026-07-07'
      summary: RCE via OpenAPI path to unescaped server route-registration string
    - id: GHSA-xrqw-w576-xgj2
      severity: medium
      published: '2026-07-07'
      summary: Package-init RCE via enum value const-block breakout injecting func init()
    - id: GHSA-rjwr-m7qx-3fjr
      severity: medium
      published: '2026-06-05'
      summary: OpenAPI server description escapes generated Go comment and injects code
  threat_note: >-
    The project's own guidance from the v2.7.2 release is "you shouldn't blindly
    trust OpenAPI specs" — the recurring class is untrusted spec content escaping
    into generated Go source.
evidence:
  - source: https://raw.githubusercontent.com/oapi-codegen/.github/main/SECURITY.md
    kind: security-policy
    http_status: 200
  - source: https://api.github.com/repos/oapi-codegen/oapi-codegen/security-advisories
    kind: advisory-registry
    http_status: 200
probes_that_missed:
  - url: https://raw.githubusercontent.com/oapi-codegen/oapi-codegen/main/SECURITY.md
    http_status: 404
  - url: https://raw.githubusercontent.com/oapi-codegen/oapi-codegen/main/.github/SECURITY.md
    http_status: 404
x-evidence:
  fetched: '2026-08-06'
  url: https://raw.githubusercontent.com/oapi-codegen/.github/main/SECURITY.md
  http_status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/oapi-codegen-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.