CVE-2026-105796
Awaiting Analysis Awaiting Analysis - Queue

Code Execution via Malicious OpenAPI Description in Kiota

Vulnerability report for CVE-2026-105796, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated documentation comment. The Java sanitizer also removes non-ASCII characters after deleting terminators, which can create a new terminator during normalization. Exploitation requires a developer or build pipeline to generate source from the malicious description and then compile and load the Java output or load the PHP output, after which injected code executes in the consuming application or build environment context. The version range is based on the Java defect and does not assert that PHP generation existed in every affected release. This issue is fixed in version 1.35.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
microsoft kiota >= 0.5.0, < 1.35.0
microsoft Microsoft.OpenApi.Kiota >= 0.5.0, < 1.35.0
microsoft Microsoft.OpenApi.Kiota.Builder >= 0.5.0, < 1.35.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kiota is a tool that generates HTTP client code from OpenAPI specifications. Between versions 0.5.0 and 1.35.0, its Java and PHP documentation sanitizers had a flaw where they removed comment terminators instead of properly neutralizing them. This allowed attackers to inject malicious OpenAPI text that could escape documentation comments and execute code in the build environment or consuming application.

Detection Guidance

Detection requires checking if your Kiota version is between 0.5.0 and 1.35.0. Run: kiota --version to check the installed version. If the version falls within this range, the system is potentially vulnerable.

Impact Analysis

If you use Kiota to generate code from a malicious OpenAPI description, an attacker could execute arbitrary code in your build environment or application. This requires the developer or pipeline to generate and compile the code, but could lead to data breaches, system compromise, or further attacks.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially causing data breaches or system compromises. Such incidents may violate compliance requirements under GDPR (data protection), HIPAA (health data), or other regulations, leading to legal penalties, fines, or reputational damage.

Mitigation Strategies

Upgrade Kiota to version 1.35.0 or later immediately. Remove or replace any generated code from vulnerable versions before compilation or deployment. Review build pipelines for malicious OpenAPI descriptions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105796. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart