Description
In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyclic graph, so the parsed YAML graph stays small, but converting that graph to System.Text.Json.Nodes.JsonNode requires every alias to be materialized as an independent node because a JsonNode cannot be attached to multiple parents. Without a bound on that conversion work, a document with N nested anchors each referenced k times can require k^N materialized JSON nodes, leading to excessive memory allocation and process termination through out-of-memory conditions, a billion laughs style denial of service. The patched versions bound the YAML-to-JSON conversion by node count and nesting depth and report an OpenApiDiagnostic error instead of expanding without limit. This vulnerability is fixed in Microsoft.OpenApi.YamlReader 2.12.0 and 3.10.0, and Microsoft.OpenApi.Readers 1.6.30.
Published: 2026-09-08
Score: 7.5 High
EPSS: 1.2% Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A small OpenAPI YAML document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed by Microsoft.OpenApi.YamlReader. The library uses SharpYaml to build a directed acyclic graph, but converting that graph to System.Text.Json.Nodes.JsonNode forces each alias to become an independent node. Without a bound, a document with N nested anchors each referenced k times can generate k^N materialized JSON nodes, exhausting memory and leading to out‑of‑memory crashes—a classic denial‑of‑service attack.

Affected Systems

The vulnerability affects Microsoft.OpenApi.YamlReader versions from 2.0.0‑preview.11 up through 2.11.x and from 3.0.0 through 3.9.x, as well as Microsoft.OpenApi.Readers versions prior to 1.6.30. The issue is resolved in Microsoft.OpenApi.YamlReader 2.12.0 and 3.10.0, and Microsoft.OpenApi.Readers 1.6.30 and later.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑impact denial of service, while the EPSS score of 1% suggests a modest likelihood of exploitation and the vulnerability is not present in the CISA KEV catalog. Based on the description, it is inferred that no authentication is required; any component that accepts user‑supplied OpenAPI definitions is at risk. The likely attack vector involves an attacker providing a malicious OpenAPI document via file upload, API consumption, or other means of influencing the parser, which can be executed remotely as long as the application processes user input.

Generated by OpenCVE AI on September 10, 2026 at 00:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Microsoft.OpenApi.YamlReader to version 2.12.0 or later or to 3.10.0 or later, and upgrade Microsoft.OpenApi.Readers to 1.6.30 or later.
  • If an upgrade is not immediately possible, enforce strict validation or sanitation of incoming OpenAPI files to limit or reject nested anchors and aliases before they reach the parser.
  • Deploy application‑level resource controls such as memory limits, container quotas, or OS‑level cgroups to mitigate the impact of potential memory exhaustion attacks.

Generated by OpenCVE AI on September 10, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft openapi.readers
Microsoft openapi.yamlreader
Vendors & Products Microsoft
Microsoft openapi.readers
Microsoft openapi.yamlreader

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.2 and from 3.0.0 until 3.10.2, and in Microsoft.OpenApi.Readers prior to 1.6.31, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyclic graph, so the parsed YAML graph stays small, but converting that graph to System.Text.Json.Nodes.JsonNode requires every alias to be materialized as an independent node because a JsonNode cannot be attached to multiple parents. Without a bound on that conversion work, a document with N nested anchors each referenced k times can require k^N materialized JSON nodes, leading to excessive memory allocation and process termination through out-of-memory conditions, a billion laughs style denial of service. The patched versions bound the YAML-to-JSON conversion by node count and nesting depth and report an OpenApiDiagnostic error instead of expanding without limit. This vulnerability is fixed in Microsoft.OpenApi.YamlReader 2.12.2 and 3.10.2, and Microsoft.OpenApi.Readers 1.6.31. In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyclic graph, so the parsed YAML graph stays small, but converting that graph to System.Text.Json.Nodes.JsonNode requires every alias to be materialized as an independent node because a JsonNode cannot be attached to multiple parents. Without a bound on that conversion work, a document with N nested anchors each referenced k times can require k^N materialized JSON nodes, leading to excessive memory allocation and process termination through out-of-memory conditions, a billion laughs style denial of service. The patched versions bound the YAML-to-JSON conversion by node count and nesting depth and report an OpenApiDiagnostic error instead of expanding without limit. This vulnerability is fixed in Microsoft.OpenApi.YamlReader 2.12.0 and 3.10.0, and Microsoft.OpenApi.Readers 1.6.30.

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.2 and from 3.0.0 until 3.10.2, and in Microsoft.OpenApi.Readers prior to 1.6.31, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyclic graph, so the parsed YAML graph stays small, but converting that graph to System.Text.Json.Nodes.JsonNode requires every alias to be materialized as an independent node because a JsonNode cannot be attached to multiple parents. Without a bound on that conversion work, a document with N nested anchors each referenced k times can require k^N materialized JSON nodes, leading to excessive memory allocation and process termination through out-of-memory conditions, a billion laughs style denial of service. The patched versions bound the YAML-to-JSON conversion by node count and nesting depth and report an OpenApiDiagnostic error instead of expanding without limit. This vulnerability is fixed in Microsoft.OpenApi.YamlReader 2.12.2 and 3.10.2, and Microsoft.OpenApi.Readers 1.6.31.
Title Microsoft.OpenApi.YamlReader/Readers vulnerable to denial of service via YAML alias expansion
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Microsoft Openapi.readers Openapi.yamlreader
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-08T17:53:05.565Z

Reserved: 2026-08-10T17:57:26.144Z

Link: CVE-2026-72923

cve-icon Vulnrichment

Updated: 2026-09-08T17:37:08.978Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:20:16.310

Modified: 2026-09-10T19:58:20.507

Link: CVE-2026-72923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T00:45:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption