oaskit
OpenAPI 3.1 validation, generation and utilities for for Elixir/Phoenix.
Activity
- Latest release
- 2mo ago
- Total releases
- 25
- Cadence
- ~7 days
- Last 12 months
- 16
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Jun 29, 2025
| Version | Released | |
|---|---|---|
0.14.2
patch
| ||
0.14.1
patch
| ||
0.14.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.13.2
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.13.1
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.13.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.12.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.10.1
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.9.1
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.8.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.2
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2026-66296
EEF-CVE-2026-66296
GHSA-h7xw-x8wr-xpcc
Aug 03, 2026
Reflected XSS in oaskit's default HTML error handler
Low
Network
Low
None
SummaryImproper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler.
Because browsers send Both HTML error rendering and the vulnerable handler are enabled by default: This issue affects oaskit: from 0.1.0 before 0.14.1. WorkaroundsDisable HTML error rendering so that validation failures are returned as JSON only:
This prevents the vulnerable HTML page from being rendered at all, on any oaskit version. Alternatively, configure a custom Affected versions
0.1.0
0.1.1
0.1.2
0.10.0
0.10.1
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.2.0
+ 11 more Show less
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
Fixed in
0.14.1
References Updated Sep 08, 2026 · Source: OSV.dev |