AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-105796.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.8CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSReceivedModified Oct 06, 2026

Disclosure summary

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated documentation comment. The Java sanitizer also removes non-ASCII characters after deleting terminators, which can create a new terminator during normalization. Exploitation requires a developer or build pipeline to generate source from the malicious description and then compile and load the Java output or load the PHP output, after which injected code executes in the consuming application or build environment context. The version range is based on the Java defect and does not assert that PHP generation existed in every affected release. This issue is fixed in version 1.35.0.

Source-reported weakness categories

CWE-94

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-rm89-rhwj-9j92

Open original source · Updated Oct 06, 2026

Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
nugetMicrosoft.OpenApi.Kiota>= 0.5.0, < 1.35.01.35.0
nugetMicrosoft.OpenApi.Kiota.Builder>= 0.5.0, < 1.35.01.35.0
NIST National Vulnerability Database · NVD-CVE-2026-105796

Open original source · Updated Oct 06, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-10-06T11:17:16-04:00
MODIFIED 2026-10-06T11:17:16-04:00
INGESTED 2026-10-06T11:45:53-04:00