Impact
A small OpenAPI YAML document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed by Microsoft.OpenApi.YamlReader. The library uses SharpYaml to build a directed acyclic graph, but converting that graph to System.Text.Json.Nodes.JsonNode forces each alias to become an independent node. Without a bound, a document with N nested anchors each referenced k times can generate k^N materialized JSON nodes, exhausting memory and leading to out‑of‑memory crashes—a classic denial‑of‑service attack.
Affected Systems
The vulnerability affects Microsoft.OpenApi.YamlReader versions from 2.0.0‑preview.11 up through 2.11.x and from 3.0.0 through 3.9.x, as well as Microsoft.OpenApi.Readers versions prior to 1.6.30. The issue is resolved in Microsoft.OpenApi.YamlReader 2.12.0 and 3.10.0, and Microsoft.OpenApi.Readers 1.6.30 and later.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑impact denial of service, while the EPSS score of 1% suggests a modest likelihood of exploitation and the vulnerability is not present in the CISA KEV catalog. Based on the description, it is inferred that no authentication is required; any component that accepts user‑supplied OpenAPI definitions is at risk. The likely attack vector involves an attacker providing a malicious OpenAPI document via file upload, API consumption, or other means of influencing the parser, which can be executed remotely as long as the application processes user input.
OpenCVE Enrichment