CVE-2026-105796 - Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators
CVE ID :CVE-2026-105796 Published : Oct. 6, 2026, 2:21 p.m. | 1 hour, 7 minutes ago Description :Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them,...