CVE-2026-73501: CWE-287: Improper Authentication in getkin kin-openapi
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.
AI Analysis
Technical Summary
The kin-openapi Go project for handling OpenAPI files has an authentication bypass vulnerability (CWE-287) in versions before 0.144.0. Specifically, ValidationHandler.Load() in openapi3filter/validation_handler.go replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without validating credentials. This causes all OpenAPI security requirements to be considered satisfied for unauthenticated requests, allowing unauthorized access to handlers that expect API keys, OAuth tokens, or other security schemes. The vulnerability is resolved in version 0.144.0.
Potential Impact
Unauthenticated attackers can bypass all OpenAPI security requirements enforced by ValidationHandler middleware, potentially gaining unauthorized access to protected API endpoints. This compromises confidentiality and integrity of the API without requiring valid credentials.
Mitigation Recommendations
Upgrade kin-openapi to version 0.144.0 or later, where this issue is fixed. Patch status is not explicitly stated beyond this fix version, so users should verify they are using 0.144.0 or newer. No other mitigations are indicated.
CVE-2026-73501: CWE-287: Improper Authentication in getkin kin-openapi
Description
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.
CVSS v3.1
Score 9.1critical
Affected software
getkin
kin-openapi
pkg:golang/github.com/getkin/kin-openapiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The kin-openapi Go project for handling OpenAPI files has an authentication bypass vulnerability (CWE-287) in versions before 0.144.0. Specifically, ValidationHandler.Load() in openapi3filter/validation_handler.go replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without validating credentials. This causes all OpenAPI security requirements to be considered satisfied for unauthenticated requests, allowing unauthorized access to handlers that expect API keys, OAuth tokens, or other security schemes. The vulnerability is resolved in version 0.144.0.
Potential Impact
Unauthenticated attackers can bypass all OpenAPI security requirements enforced by ValidationHandler middleware, potentially gaining unauthorized access to protected API endpoints. This compromises confidentiality and integrity of the API without requiring valid credentials.
Mitigation Recommendations
Upgrade kin-openapi to version 0.144.0 or later, where this issue is fixed. Patch status is not explicitly stated beyond this fix version, so users should verify they are using 0.144.0 or newer. No other mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-12T19:00:33.736Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7ce89cbf8831d5393450fa
Added to database: 08/12/2026, 21:41:48 UTC
Last enriched: 08/12/2026, 21:56:05 UTC
Last updated: 09/26/2026, 13:47:48 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.