Junglewise Threat Intelligence

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

Severity: low · CVSS 3.1 · Published 2026-07-17

Technologies: github.com/oapi-codegen/oapi-codegen/v2 (Go). Vendors: Go.

Executive brief

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

Affected products

  • Go github.com/oapi-codegen/oapi-codegen/v2

Related threats