generated: '2026-08-06' method: searched probe: true source: https://github.com/oapi-codegen/.github/blob/main/SECURITY.md scope: >- oapi-codegen has no hosted surface of its own — it is distributed as Go modules and lives entirely in the oapi-codegen GitHub organisation. Its disclosure programme is therefore an org-level SECURITY.md plus GitHub Security Advisories, not a /.well-known/security.txt on a company domain. policy: - https://github.com/oapi-codegen/.github/blob/main/SECURITY.md contact: - channel: github-security-advisories url: https://github.com/oapi-codegen/oapi-codegen/security/advisories/ note: >- Coordinated disclosure via the GitHub security advisories page for the affected repository. Public issues, discussions, and pull requests are explicitly not an acceptable reporting channel. model: coordinated-disclosure bug_bounty: null supported_versions: latest minor release only (backports considered by severity) dependency_policy: summary: >- Dependency CVEs are patched when exploitable under static analysis via govulncheck, when a fix requires a code change plus version bump, or during routine dependency hygiene. Consumers may override dependency versions in their own go.mod ahead of an upstream release. tool: https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck advisories_published: registry: https://github.com/oapi-codegen/oapi-codegen/security/advisories recent: - id: GHSA-9c2f-gr95-7wqw severity: medium published: '2026-07-21' summary: OpenAPI x-go-type-import generated Go code injection - id: GHSA-jwgf-6xff-4hvp severity: medium published: '2026-07-07' summary: RCE via OpenAPI path to unescaped server route-registration string - id: GHSA-xrqw-w576-xgj2 severity: medium published: '2026-07-07' summary: Package-init RCE via enum value const-block breakout injecting func init() - id: GHSA-rjwr-m7qx-3fjr severity: medium published: '2026-06-05' summary: OpenAPI server description escapes generated Go comment and injects code threat_note: >- The project's own guidance from the v2.7.2 release is "you shouldn't blindly trust OpenAPI specs" — the recurring class is untrusted spec content escaping into generated Go source. evidence: - source: https://raw.githubusercontent.com/oapi-codegen/.github/main/SECURITY.md kind: security-policy http_status: 200 - source: https://api.github.com/repos/oapi-codegen/oapi-codegen/security-advisories kind: advisory-registry http_status: 200 probes_that_missed: - url: https://raw.githubusercontent.com/oapi-codegen/oapi-codegen/main/SECURITY.md http_status: 404 - url: https://raw.githubusercontent.com/oapi-codegen/oapi-codegen/main/.github/SECURITY.md http_status: 404 x-evidence: fetched: '2026-08-06' url: https://raw.githubusercontent.com/oapi-codegen/.github/main/SECURITY.md http_status: 200