We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Aimed at the tooling creators to protect the users of their tools from maliciously created OAS descriptions.
The text was updated successfully, but these errors were encountered:
OAS inherits security considerations from YAML and JSON.
JSON Security Considerations from RFC 8259
YAML billion laughs attack
lol1: &lol1 ["lol","lol","lol","lol","lol","lol","lol","lol","lol"] lol2: &lol2 [*lol1,*lol1,*lol1,*lol1,*lol1,*lol1,*lol1,*lol1,*lol1] lol3: &lol3 [*lol2,*lol2,*lol2,*lol2,*lol2,*lol2,*lol2,*lol2,*lol2] lol4: &lol4 [*lol3,*lol3,*lol3,*lol3,*lol3,*lol3,*lol3,*lol3,*lol3] lol5: &lol5 [*lol4,*lol4,*lol4,*lol4,*lol4,*lol4,*lol4,*lol4,*lol4] lol6: &lol6 [*lol5,*lol5,*lol5,*lol5,*lol5,*lol5,*lol5,*lol5,*lol5] lol7: &lol7 [*lol6,*lol6,*lol6,*lol6,*lol6,*lol6,*lol6,*lol6,*lol6] lol8: &lol8 [*lol7,*lol7,*lol7,*lol7,*lol7,*lol7,*lol7,*lol7,*lol7] lol9: &lol9 [*lol8,*lol8,*lol8,*lol8,*lol8,*lol8,*lol8,*lol8,*lol8] lolz: &lolz [*lol9]
Sorry, something went wrong.
Incorrect input sanitization in code-generator tools can result in generated code being poisoned. See https://github.com/Mermade/openapi3-examples/tree/master/3.0/malicious
darrelmiller
Successfully merging a pull request may close this issue.
Aimed at the tooling creators to protect the users of their tools from maliciously created OAS descriptions.
The text was updated successfully, but these errors were encountered: