What is CVE-2026-73851?
CVE-2026-73851 is a path traversal vulnerability in Kiota, an OpenAPI-based HTTP Client code generator. An attacker can exploit malicious OpenAPI descriptions to resolve file references outside the manifest package, potentially reading sensitive files. Versions prior to 1.29.1 and 1.34.0 are affected; immediate patching is advised.
Azərbaycanca: CVE-2026-73851 Kiota OpenAPI əsaslı HTTP Client kod generatorunda aşkarlanan path traversal zəifliyidir. Təcavüzkar, idarə etdiyi və ya dəyişdirdiyi OpenAPI təsviri vasitəsilə paket xaricinə çıxan fayl referansı təmin edərək sistemdəki həssas faylları oxuya bilər. 1.29.1 və 1.34.0 versiyalarından əvvəlki versiyalar təsirlənir, dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which product does CVE-2026-73851 affect?
CVE-2026-73851 affects Kiota, an OpenAPI-based HTTP Client code generator.
Which Kiota versions are recommended to patch CVE-2026-73851?
This vulnerability affects versions prior to 1.29.1 and 1.34.0, so immediate patching to these versions or newer is advised.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.