Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v2x6-wwfw-r2rq | Agentgateway is missing parameter sanitization in MCP to OpenAPI conversion |
Wed, 18 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfprojects
Lfprojects agentgateway |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:lfprojects:agentgateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfprojects
Lfprojects agentgateway |
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agentgateway
Agentgateway agentgateway |
|
| Vendors & Products |
Agentgateway
Agentgateway agentgateway |
Fri, 06 Mar 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environment. Prior to version 0.12.0, when converting MCP tools/call request to OpenAPI request, input path, query, and header values are not sanitized. This issue has been patched in version 0.12.0. | |
| Title | Agentgateway: Missing parameter sanitization in MCP to OpenAPI conversion | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-09T20:54:30.319Z
Reserved: 2026-03-04T16:26:02.900Z
Link: CVE-2026-29791
Updated: 2026-03-09T20:51:42.473Z
Status : Analyzed
Published: 2026-03-06T21:16:15.787
Modified: 2026-03-18T19:03:44.357
Link: CVE-2026-29791
No data.
OpenCVE Enrichment
Updated: 2026-04-16T11:15:27Z
Github GHSA