CVE-2023-27162
Critical · CVSS 9.1openapi-generator (org.openapitools:openapi-generator-project) — Server-Side Request Forgery (SSRF)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-918, CWE-918
Description
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
Search profile — drives PoC discovery
Symbols /api/gen/clients/{language}openapi-generator-projectorg.openapitoolsopenapi-generator
Keywords CVE-2023-27162openapi-generator SSRFopenapi-generator 6.4.0/api/gen/clients SSRFopenapi-generator Server-Side Request Forgeryopenapi-generator-project SSRFb33t1e openapi SSRFopenapi-generator PoC
Versions: <= 6.4.0
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0limithit/modsecurity-rule needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Maven | org.openapitools:openapi-generator-project | 0 → ∞ |
References
- https://gist.github.com/b33t1e/6121210ebd9efd4f693c73b830d8ab08
- https://github.com/OpenAPITools/openapi-generator
- https://notes.sjtu.edu.cn/s/2_yki_2Xq
- http://openapi-generator.com
- https://gist.github.com/b33t1e/6121210ebd9efd4f693c73b830d8ab08
- https://github.com/OpenAPITools/openapi-generator
- https://notes.sjtu.edu.cn/s/2_yki_2Xq
- https://gist.github.com/b33t1e/6121210ebd9efd4f693c73b830d8ab08
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z