Swashbuckle.AspNetCore.SwaggerUI
Middleware to expose an embedded version of the swagger-ui from an ASP.NET Core application
Activity
- Latest release
- 2mo ago
- Total releases
- 101
- Cadence
- ~15 days
- Last 12 months
- 15
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jan 03, 2017
| Version | Released | |
|---|---|---|
10.2.3
patch
| ||
10.2.2
patch
| ||
10.2.1
patch
| ||
10.2.0
minor
| ||
10.1.7
patch
| ||
10.1.6
patch
| ||
10.1.5
patch
| ||
10.1.4
patch
| ||
10.1.3
patch
| ||
10.1.2
patch
| ||
10.1.1
patch
| ||
10.1.0
minor
| ||
10.0.1
patch
| ||
10.0.0
major
| ||
9.0.6
patch
| ||
9.0.5
patch
| ||
9.0.4
patch
| ||
9.0.3
patch
| ||
9.0.2
patch
| ||
9.0.1
patch
| ||
9.0.0
major
| ||
8.1.4
patch
| ||
8.1.3
patch
| ||
8.1.2
patch
| ||
8.1.1
patch
| ||
8.1.0
minor
| ||
8.0.0
major
| ||
7.3.2
patch
| ||
7.3.1
patch
| ||
7.3.0
minor
| ||
7.2.0
minor
| ||
7.1.0
minor
| ||
7.0.0
major
| ||
6.9.0
minor
| ||
6.8.1
patch
| ||
6.8.0
minor
| ||
6.7.3
patch
| ||
6.7.2
patch
| ||
6.7.1
patch
| ||
6.7.0
minor
| ||
6.6.2
patch
| ||
6.6.1
minor
| ||
6.6.0-preview.322
pre
| ||
6.5.0
minor
| ||
6.4.0
minor
| ||
6.3.1
patch
| ||
6.3.0
minor
| ||
6.2.3
patch
1 CVE
GHSA-qrmm-w75w-3wpx
Dec 09, 2021
Server side request forgery in SwaggerUI
Medium
SwaggerUI supports displaying remote OpenAPI definitions through the However, this functionality may pose a risk for users who host their own SwaggerUI instances. In particular, including remote OpenAPI definitions opens a vector for phishing attacks by abusing the trusted names/domains of self-hosted instances. An example scenario abusing this functionality could take the following form:
We do want to stress that this attack vector is limited to scenarios that actively trick users into divulging sensitive information. The ease of this is highly contextual and, therefore, the threat model may be different for individual users and organizations. It is not possible to perform non-interactive attacks (e.g., cross-site scripting or code injection) through this mechanism. ResolutionWe've made the decision to disable query parameters (#4872) by default starting with SwaggerUI version WorkaroundIf you host a version of SwaggerUI and wish to mitigate this issue immediately, you are encouraged to add the following custom plugin code:
Future UX workThrough the exploration of this issue, it became apparent that users may not be aware to which web server the Try-it-out function will send requests. While this information is currently presented at the top of the page, understanding may improve by displaying it closer to the "Execute" button where requests are actually made. We'll be exploring these UX improvements over the coming months and welcome community input. Please create a Feature Request under the GitHub Issue tab to start a conversation with us and the community. Reflected XSS attackWarning in versions < 3.38.0, it is possible to combine the URL options (as mentioned above) with a vulnerability in DOMPurify (https://www.cvedetails.com/cve/CVE-2020-26870/) to create a reflected XSS vector. If your version of Swagger UI is older than 3.38.0, we suggest you upgrade or implement the workaround as mentioned above. Affected versions
1.0.0
1.0.0--rc1
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.1.0
1.2.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
+ 45 more Show less
2.4.0
2.5.0
3.0.0
4.0.0
4.0.1
5.0.0
5.0.0-beta
5.0.0-rc1
5.0.0-rc2
5.0.0-rc3
5.0.0-rc4
5.0.0-rc5
5.1.0
5.2.0
5.2.1
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.5.0
5.5.1
5.6.0
5.6.1
5.6.2
5.6.3
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.2.0
6.2.1
6.2.2
6.2.3
Fixed in
6.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
6.2.2
patch
1 CVE
GHSA-qrmm-w75w-3wpx
Dec 09, 2021
Server side request forgery in SwaggerUI
Medium
SwaggerUI supports displaying remote OpenAPI definitions through the However, this functionality may pose a risk for users who host their own SwaggerUI instances. In particular, including remote OpenAPI definitions opens a vector for phishing attacks by abusing the trusted names/domains of self-hosted instances. An example scenario abusing this functionality could take the following form:
We do want to stress that this attack vector is limited to scenarios that actively trick users into divulging sensitive information. The ease of this is highly contextual and, therefore, the threat model may be different for individual users and organizations. It is not possible to perform non-interactive attacks (e.g., cross-site scripting or code injection) through this mechanism. ResolutionWe've made the decision to disable query parameters (#4872) by default starting with SwaggerUI version WorkaroundIf you host a version of SwaggerUI and wish to mitigate this issue immediately, you are encouraged to add the following custom plugin code:
Future UX workThrough the exploration of this issue, it became apparent that users may not be aware to which web server the Try-it-out function will send requests. While this information is currently presented at the top of the page, understanding may improve by displaying it closer to the "Execute" button where requests are actually made. We'll be exploring these UX improvements over the coming months and welcome community input. Please create a Feature Request under the GitHub Issue tab to start a conversation with us and the community. Reflected XSS attackWarning in versions < 3.38.0, it is possible to combine the URL options (as mentioned above) with a vulnerability in DOMPurify (https://www.cvedetails.com/cve/CVE-2020-26870/) to create a reflected XSS vector. If your version of Swagger UI is older than 3.38.0, we suggest you upgrade or implement the workaround as mentioned above. Affected versions
1.0.0
1.0.0--rc1
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.1.0
1.2.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
+ 45 more Show less
2.4.0
2.5.0
3.0.0
4.0.0
4.0.1
5.0.0
5.0.0-beta
5.0.0-rc1
5.0.0-rc2
5.0.0-rc3
5.0.0-rc4
5.0.0-rc5
5.1.0
5.2.0
5.2.1
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.5.0
5.5.1
5.6.0
5.6.1
5.6.2
5.6.3
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.2.0
6.2.1
6.2.2
6.2.3
Fixed in
6.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
6.2.1
patch
1 CVE
GHSA-qrmm-w75w-3wpx
Dec 09, 2021
Server side request forgery in SwaggerUI
Medium
SwaggerUI supports displaying remote OpenAPI definitions through the However, this functionality may pose a risk for users who host their own SwaggerUI instances. In particular, including remote OpenAPI definitions opens a vector for phishing attacks by abusing the trusted names/domains of self-hosted instances. An example scenario abusing this functionality could take the following form:
We do want to stress that this attack vector is limited to scenarios that actively trick users into divulging sensitive information. The ease of this is highly contextual and, therefore, the threat model may be different for individual users and organizations. It is not possible to perform non-interactive attacks (e.g., cross-site scripting or code injection) through this mechanism. ResolutionWe've made the decision to disable query parameters (#4872) by default starting with SwaggerUI version WorkaroundIf you host a version of SwaggerUI and wish to mitigate this issue immediately, you are encouraged to add the following custom plugin code:
Future UX workThrough the exploration of this issue, it became apparent that users may not be aware to which web server the Try-it-out function will send requests. While this information is currently presented at the top of the page, understanding may improve by displaying it closer to the "Execute" button where requests are actually made. We'll be exploring these UX improvements over the coming months and welcome community input. Please create a Feature Request under the GitHub Issue tab to start a conversation with us and the community. Reflected XSS attackWarning in versions < 3.38.0, it is possible to combine the URL options (as mentioned above) with a vulnerability in DOMPurify (https://www.cvedetails.com/cve/CVE-2020-26870/) to create a reflected XSS vector. If your version of Swagger UI is older than 3.38.0, we suggest you upgrade or implement the workaround as mentioned above. Affected versions
1.0.0
1.0.0--rc1
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.1.0
1.2.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
+ 45 more Show less
2.4.0
2.5.0
3.0.0
4.0.0
4.0.1
5.0.0
5.0.0-beta
5.0.0-rc1
5.0.0-rc2
5.0.0-rc3
5.0.0-rc4
5.0.0-rc5
5.1.0
5.2.0
5.2.1
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.5.0
5.5.1
5.6.0
5.6.1
5.6.2
5.6.3
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.2.0
6.2.1
6.2.2
6.2.3
Fixed in
6.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev |