Swagger's vulnerability footprint is concentrated in API documentation and code-generation tooling, particularly the widely embedded swagger-codegen and swagger-parser components that developers use to build service clients and validate specifications. The observed weakness class centers on deserialization of untrusted data, reflecting the parsing and object-instantiation demands of handling external API schemas; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Swagger over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000207HIGH A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously cr | Nov 27, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-1000208HIGH A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification i | Nov 17, 2017 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Swagger.
Media articles that mention a CVE ID that affects a product developed by Swagger — matched by CVE ID, not by vendor name.