Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cr3q-pqgq-m8c2 | Spoofing attack in swagger-ui |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:26:39.523Z
Reserved: 2022-03-11T00:00:00.000Z
Link: CVE-2018-25031
Updated: 2024-08-05T12:26:39.523Z
Status : Modified
Published: 2022-03-11T07:15:07.190
Modified: 2024-11-21T04:03:23.847
Link: CVE-2018-25031
No data.
OpenCVE Enrichment
No data.
Github GHSA