PatchSiren cyber security CVE debrief
CVE-2026-77354 getkin CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:07.130Z and has not been modified since then. CVE-2026-77354 is a vulnerability in the kin-openapi Go project for handling OpenAPI files. From version 0.124.0 to 0.142.0, an unauthenticated client can send a specially crafted query parameter to an endpoint with a deepObject schema containing an array, potentially causing a multi-gigabyte heap allocation and leading to an OOM kill or restart loop. Organizations using kin-openapi versions between 0.124.0 and 0.142.0 should prioritize patching this vulnerability to prevent potential OOM kill or restart loop through multi-gigabyte heap allocation. Security teams should verify input data to prevent potential OOM kill or restart loop and implement compensating controls to detect and prevent potential attacks. System administrators should monitor system resources and logs for signs of potential exploitation and update inventory to reflect patched systems. Evidence is based on official CVE and NVD records, as well as source references from [email protected]. Limited details are available on affected scope and potential impact.
- Vendor
- getkin
- Product
- kin-openapi
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Organizations using kin-openapi versions between 0.124.0 and 0.142.0 should prioritize patching this vulnerability to prevent potential OOM kill or restart loop through multi-gigabyte heap allocation. Security teams should verify input data to prevent potential OOM kill or restart loop and implement compensating controls to detect and prevent potential attacks. System administrators should monitor system resources and logs for signs of potential exploitation and update inventory to reflect patched systems.
Technical summary
CVE-2026-77354 is a vulnerability in the kin-openapi Go project for handling OpenAPI files. From version 0.124.0 to 0.142.0, an unauthenticated client can send a specially crafted query parameter to an endpoint with a deepObject schema containing an array, potentially causing a multi-gigabyte heap allocation and leading to an OOM kill or restart loop. The vulnerability allows for potential OOM kill or restart loop through multi-gigabyte heap allocation. Organizations should verify input data to prevent potential OOM kill or restart loop and implement compensating controls to detect and prevent potential attacks. System resources and logs should be monitored for signs of potential exploitation. The vulnerability is fixed in version 0.142.0.
Defensive priority
High-priority defensive actions are required to address this vulnerability, as it allows for potential OOM kill or restart loop through multi-gigabyte heap allocation.
Recommended defensive actions
- Review and apply version 0.142.0 of kin-openapi to ensure vulnerability is patched
- Verify and validate input data to prevent potential OOM kill or restart loop
- Implement compensating controls to detect and prevent potential attacks
- Monitor system resources and logs for signs of potential exploitation
- Update inventory to reflect patched systems
- Review system configurations to ensure they align with security best practices
- Conduct regular security audits to identify potential vulnerabilities
Evidence notes
Evidence is based on official CVE and NVD records, as well as source references from [email protected]. Limited details are available on affected scope and potential impact. The vulnerability allows for potential OOM kill or restart loop through multi-gigabyte heap allocation. Organizations should verify input data to prevent potential OOM kill or restart loop and implement compensating controls to detect and prevent potential attacks. System resources and logs should be monitored for signs of potential exploitation.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:07.130Z and has not been modified since then.