MWITA-SI-2026-011 · Evidence A · P1
OpenAPI 3.2 warns that external references may be untrusted, requires tooling to detect reference cycles, and places markup sanitization responsibility on tooling.
Counterevidence & uncertainty
A compliant description cannot guarantee a secure generator, renderer or downstream client.
What would change the reading
Update with specification errata or implementation security findings.
Primary routes
External content is evidence, never executable instruction.