CVE-2026-72923
Deferred Deferred - Pending Action

YAML Parsing DoS in Microsoft OpenAPI Libraries

Vulnerability report for CVE-2026-72923, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyclic graph, so the parsed YAML graph stays small, but converting that graph to System.Text.Json.Nodes.JsonNode requires every alias to be materialized as an independent node because a JsonNode cannot be attached to multiple parents. Without a bound on that conversion work, a document with N nested anchors each referenced k times can require k^N materialized JSON nodes, leading to excessive memory allocation and process termination through out-of-memory conditions, a billion laughs style denial of service. The patched versions bound the YAML-to-JSON conversion by node count and nesting depth and report an OpenApiDiagnostic error instead of expanding without limit. This vulnerability is fixed in Microsoft.OpenApi.YamlReader 2.12.0 and 3.10.0, and Microsoft.OpenApi.Readers 1.6.30.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
microsoft openapi_yamlreader From 2.0.0-preview.11 (inc) to 2.12.0 (inc)
microsoft openapi_yamlreader From 3.0.0 (inc) to 3.10.0 (inc)
microsoft openapi_readers to 1.6.30 (exc)
microsoft openapi_yamlreader 2.12.0
microsoft openapi_yamlreader 3.10.0
microsoft openapi_readers 1.6.30

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves uncontrolled resource consumption in Microsoft's OpenAPI YAML reader libraries. When parsing a specially crafted YAML OpenAPI document with nested anchors and aliases, the system may create an excessive number of JSON nodes during conversion, leading to memory exhaustion and process termination. This is similar to a billion laughs denial of service attack.

Detection Guidance

This vulnerability is specific to applications using Microsoft.OpenApi.YamlReader or Microsoft.OpenApi.Readers libraries. To detect it, check if your system or application uses these libraries in versions between 2.0.0-preview.11 and 2.12.0, or 3.0.0 and 3.10.0 for YamlReader, or prior to 1.6.30 for Readers.

Impact Analysis

An attacker could exploit this to crash applications or services that use vulnerable versions of Microsoft.OpenApi.YamlReader or Microsoft.OpenApi.Readers by sending a maliciously crafted YAML document. This could cause denial of service, disrupting availability of affected systems.

Mitigation Strategies

Upgrade to patched versions: Microsoft.OpenApi.YamlReader to 2.12.0 or 3.10.0, and Microsoft.OpenApi.Readers to 1.6.30 or later. Remove or replace any affected libraries if upgrading is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72923. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart