An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS0yamNjLW14djctcDNmOc4ABaUm

Moderate CVSS: 6.0

oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)

Affected Packages Affected Versions Fixed Versions
go:github.com/oasdiff/oasdiff
PURL: pkg:go/github.com%2Foasdiff%2Foasdiff
>= 1.13.2, <= 1.18.0 1.18.1
0 Dependent packages
0 Dependent repositories

Affected Version Ranges

All affected versions

v1.13.2, v1.13.3, v1.13.4, v1.13.5, v1.14.0, v1.15.0, v1.15.0-openapi31.beta.1, v1.15.0-openapi31.beta.2, v1.15.0-openapi31.beta.3, v1.15.1, v1.15.2, v1.15.3, v1.16.0, v1.17.0, v1.18.0

All unaffected versions

v0.0.1, v0.0.2, v0.0.3, v0.0.4, v0.0.5, v0.0.6, v0.0.7, v0.0.8, v0.0.9, v0.0.10, v0.1.0, v0.1.1, v0.1.2, v0.1.3, v0.1.4, v0.1.5, v0.1.6, v0.1.7, v0.1.8, v0.1.9, v0.1.10, v0.1.11, v0.1.12, v0.1.13, v0.1.14, v0.1.15, v0.1.16, v0.1.17, v0.1.18, v0.1.19, v0.1.20, v0.1.21, v0.2.1, v0.2.2, v0.2.3, v0.2.4, v0.2.5, v0.2.6, v0.2.7, v0.2.8, v0.2.9, v0.2.10, v0.3.1, v0.3.2, v0.3.3, v0.3.4, v0.3.5, v0.3.6, v0.3.7, v0.3.8, v0.3.9, v0.4.0, v0.4.1, v0.4.2, v0.4.3, v0.4.4, v0.4.5, v0.4.6, v0.4.7, v0.4.8, v0.4.9, v0.5.1, v0.5.2, v0.5.3, v0.5.4, v0.5.6, v0.5.7, v0.5.8, v0.5.9, v1.0.0, v1.0.1, v1.0.2, v1.0.3, v1.0.4, v1.0.5, v1.0.6, v1.0.7, v1.0.8, v1.0.9, v1.1.0, v1.1.1, v1.1.2, v1.1.3, v1.1.4, v1.1.5, v1.1.6, v1.1.7, v1.1.8, v1.1.9, v1.1.10, v1.1.11, v1.1.12, v1.1.13, v1.1.14, v1.1.15, v1.1.16, v1.1.17, v1.1.18, v1.1.19, v1.1.20, v1.1.21, v1.1.22, v1.1.23, v1.1.24, v1.1.25, v1.1.26, v1.1.27, v1.1.28, v1.1.29, v1.1.30, v1.1.31, v1.1.32, v1.1.33, v1.1.34, v1.1.35, v1.1.36, v1.1.37, v1.1.38, v1.1.39, v1.1.40, v1.2.0, v1.2.1, v1.2.2, v1.2.3, v1.2.4, v1.2.5, v1.2.6, v1.2.7, v1.2.8, v1.2.9, v1.3.0, v1.3.1, v1.3.3, v1.3.4, v1.3.5, v1.3.6, v1.3.7, v1.3.8, v1.3.9, v1.3.10, v1.3.11, v1.3.12, v1.3.13, v1.3.14, v1.3.15, v1.3.16, v1.3.17, v1.3.18, v1.3.19, v1.3.20, v1.3.21, v1.3.22, v1.3.23, v1.4.0, v1.4.1, v1.4.2, v1.5.0, v1.5.1, v1.5.2, v1.5.3, v1.5.4, v1.5.5, v1.5.6, v1.5.7, v1.5.8, v1.5.9, v1.5.10, v1.5.11, v1.5.12, v1.5.13, v1.5.14, v1.5.15, v1.5.16, v1.5.17, v1.5.18, v1.5.19, v1.5.20, v1.6.0, v1.6.1, v1.6.2, v1.6.3, v1.6.4, v1.6.5, v1.6.6, v1.7.0, v1.7.1, v1.7.2, v1.7.3, v1.7.4, v1.7.5, v1.7.6, v1.7.7, v1.7.8, v1.7.9, v1.7.10, v1.8.0, v1.8.1, v1.9.0, v1.9.1, v1.9.2, v1.9.3, v1.9.4, v1.9.5, v1.9.6, v1.9.7, v1.9.8, v1.10.0, v1.10.1, v1.10.2, v1.10.3, v1.10.4, v1.10.5, v1.10.6, v1.10.7, v1.10.8, v1.10.9, v1.10.10, v1.10.11, v1.10.12, v1.10.13, v1.10.14, v1.10.15, v1.10.16, v1.10.17, v1.10.18, v1.10.19, v1.10.20, v1.10.21, v1.10.22, v1.10.23, v1.10.24, v1.10.25, v1.10.26, v1.10.27, v1.10.28, v1.10.29, v1.11.0, v1.11.1, v1.11.2, v1.11.3, v1.11.4, v1.11.5, v1.11.6, v1.11.7, v1.11.8, v1.11.9, v1.11.10, v1.11.11, v1.12.0, v1.12.1, v1.12.2, v1.12.3, v1.12.4, v1.12.5, v1.12.6, v1.12.7, v1.12.8, v1.12.9, v1.13.0, v1.13.1, v1.18.1, v1.18.2, v1.18.3, v1.18.4, v1.18.5, v1.18.6, v1.19.0

Summary

From v1.13.2 through v1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from a git revision (the rev:path form, e.g. main:openapi.yaml). External $refs were resolved on that load path even when external refs were explicitly disabled, so the mitigation silently did not apply there.

Impact

A caller who set --allow-external-refs=false specifically to safely process untrusted specs remained exposed — on the git-revision load path only — to:

  • SSRF via $ref: "http://<internal-host>/…", and
  • Local file reads via $ref: "/path" or file://.

Affected callers:

  • CLI: oasdiff diff main:openapi.yaml HEAD:openapi.yaml --allow-external-refs=false (and breaking / changelog / summary, and the git-diff-driver) run over untrusted spec content.
  • Go library consumers of github.com/oasdiff/oasdiff/load that set IsExternalRefsAllowed = false and load from a git-revision source via load.NewSpecInfo.

The file and URL load paths correctly enforced the setting; only the git-revision path was affected. Callers that left external refs at the default (true) are not in scope for this advisory.

Patches

v1.18.1 enforces the external-refs policy on the git-revision path (so --allow-external-refs=false now blocks external $refs there) and returns a dedicated exit code (123) when an external $ref is refused.

Workarounds

  • Upgrade to v1.18.1, or
  • Avoid the git-revision input form when processing untrusted specs with external refs disabled.

Notes

  • Introduced in v1.13.2 (#832, which added $ref-chain resolution on the git-revision path); fixed in v1.18.1 (#974, #975).
  • The permissive default (allow-external-refs: true) and its zero-interaction exposure in CI via the GitHub Action is tracked separately in GHSA-fhj3-7267-7vv5 (oasdiff-action).
References: