VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5670 CVEsRSS

CVE-2024-58384Medium· 5.4
1w ago

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitr…

▾ Sunlittornadoweb · tornadoEPSS 0.24%via NVD
CVE-2024-14029High· 7.5PoC⚖ disputed
1w ago

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deploye…

▾ Midnighttornadoweb · tornadoEPSS 0.35%via NVD
CVE-2023-54397High· 7.5
1w ago

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy val…

▾ Twilighttornadoweb · tornadoEPSS 0.37%via NVD
CVE-2026-91990High· 7.5PoC
1w ago

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create lar…

▾ Midnighttornadoweb · tornadoEPSS 0.49%via NVD
CVE-2026-91987Medium· 6.5
1w ago

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers…

▾ Sunlitdep0we · atomic-agents-stackEPSS 0.48%via NVD
CVE-2026-91989High· 7.5
1w ago

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass …

▾ Twilightdep0we · atomic-agents-stackEPSS 1.3%via NVD
CVE-2026-91988High· 8.1
1w ago

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argume…

▾ Twilightdep0we · atomic-agents-stackEPSS 0.32%via NVD
CVE-2026-91992Medium· 5.9PoC
1w ago

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…

▾ Twilighttornadoweb · tornadoEPSS 0.26%via NVD
CVE-2026-91991Medium· 5.4PoC
1w ago

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-de…

▾ Twilighttornadoweb · tornadoEPSS 0.28%via NVD
CVE-2026-57586High· 8.6
1w ago

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/mana…

▾ Twilightnaranor · agent-coderagEPSS 0.21%via NVD
CVE-2026-59971Critical· 10.0
1w ago

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_se…

▾ Midnightdesigncomputer · mysql_mcp_serverEPSS 0.42%via NVD
CVE-2026-59157Medium· 6.5
1w ago

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParam…

▾ Sunlitncarlier · webhookdEPSS 0.60%via NVD
CVE-2026-50024Medium· 5.3
1w ago

GitHacker is a tool that restores Git repositories from exposed .git directories

GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs…

▾ SunlitWangYihang · GitHackerEPSS 0.45%via NVD
CVE-2026-53710Critical· 10.0
1w ago

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw geta…

▾ MidnightIBM · mcp-context-forgeEPSS 1.1%via NVD
CVE-2026-54168Medium· 6.5
1w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …

▾ Sunlittektoncd · pipelines-as-codeEPSS 0.59%via NVD
CVE-2026-57112High· 8.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legac…

▾ MidnightMervinPraison · PraisonAIEPSS 0.22%via NVD
CVE-2026-57148Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance …

▾ AbyssalMervinPraison · PraisonAIEPSS 0.64%via NVD
CVE-2026-57147Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run whe…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.77%via NVD
CVE-2026-54503Medium· 4.3
1w ago

plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type

plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored…

▾ Sunlitplone · plone.app.textfieldEPSS 0.40%via NVD
CVE-2026-53954Medium· 4.3
1w ago

Bugsink is a self-hosted error tracking tool

Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a caller with a valid project DSN to submit an unusually large tag set and force exce…

▾ Sunlitbugsink · bugsinkEPSS 0.56%via NVD
CVE-2026-55770Medium· 6.8PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…

▾ Twilightopenbao · openbaoEPSS 0.53%via NVD
CVE-2026-55774Low· 2.1
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…

▾ Sunlitopenbao · openbaoEPSS 0.56%via NVD
CVE-2026-55775Low· 2.3⚖ disputed
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespa…

▾ Sunlitopenbao · openbaoEPSS 0.48%via NVD
CVE-2026-55776Medium· 6.5PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type paramete…

▾ Twilightopenbao · openbaoEPSS 0.61%via NVD
MAL-2026-16203Critical⚠ Exploited
2w ago

Malicious code in faiss-cpu-avx512 (PyPI)

Malicious code in faiss-cpu-avx512 (PyPI)

▾ Abyssalfaiss-cpu-avx512 · faiss-cpu-avx512via OSV
CVE-2026-56668High· 8.1
2w ago

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.41%via OSV
CVE-2026-76081Medium· 5.5
2w ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue s…

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.40%via NVD
CVE-2026-73496High· 7.7PoC
2w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src…

▾ Midnightsooperset · mcp-atlassianEPSS 0.48%via NVD
CVE-2026-73497Medium· 6.5
2w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url hea…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.38%via NVD
CVE-2026-65838High· 8.2
2w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass …

▾ Twilightzalando · skipperEPSS 0.46%via NVD
CVEs tagged “osv” — page 10 · VulnSea