Tagged “osv”
CVEs tagged osv, newest first.
5666 CVEsRSS
CVE-2026-53715Medium· 5.3Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map…
CVE-2026-53713Critical· 9.1Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not col…
CVE-2026-53714High· 7.4Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…
CVE-2026-54334Critical· 9.8UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT …
CVE-2026-54333Critical· 9.8UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read…
RUSTSEC-2026-0283Noneclear_on_drop is unmaintained
clear_on_drop is unmaintained
MAL-2026-16143Critical⚠ ExploitedMalicious code in chroma-client (PyPI)
Malicious code in chroma-client (PyPI)
RUSTSEC-2026-0298NoneUse-after-free when a future's `Drop` panics while the container is dropped
Use-after-free when a future's `Drop` panics while the container is dropped
CVE-2026-90553High· 7.8vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbi…
MAL-2026-16142Critical⚠ ExploitedMalicious code in python-fork (PyPI)
Malicious code in python-fork (PyPI)
MAL-2026-16164Critical⚠ ExploitedMalicious code in logs_update (crates.io)
Malicious code in logs_update (crates.io)
CVE-2026-89090Medium· 5.9An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …
An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …
MAL-2026-16141Critical⚠ ExploitedMalicious code in platform-telemetry-client (PyPI)
Malicious code in platform-telemetry-client (PyPI)
MAL-2026-16136Critical⚠ ExploitedMalicious code in transfomers (PyPI)
Malicious code in transfomers (PyPI)
MAL-2026-16135Critical⚠ ExploitedMalicious code in openaii (PyPI)
Malicious code in openaii (PyPI)
MAL-2026-16134Critical⚠ ExploitedMalicious code in ollamaa (PyPI)
Malicious code in ollamaa (PyPI)
MAL-2026-16133Critical⚠ ExploitedMalicious code in langgrap (PyPI)
Malicious code in langgrap (PyPI)
MAL-2026-16131Critical⚠ ExploitedMalicious code in aitextutils-py (PyPI)
Malicious code in aitextutils-py (PyPI)
MAL-2026-16130Critical⚠ ExploitedMalicious code in aitextkit-py (PyPI)
Malicious code in aitextkit-py (PyPI)
MAL-2026-16129Critical⚠ ExploitedMalicious code in web3-eth-account (PyPI)
Malicious code in web3-eth-account (PyPI)
MAL-2026-16128Critical⚠ ExploitedMalicious code in pymem-win (PyPI)
Malicious code in pymem-win (PyPI)
MAL-2026-16127Critical⚠ ExploitedMalicious code in eth-account-web3 (PyPI)
Malicious code in eth-account-web3 (PyPI)
CVE-2026-56665Medium· 4.2ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
CVE-2026-59151Critical· 9.6Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
CVE-2026-88046Medium· 5.3rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk…
CVE-2026-88018Critical· 9.8PoCrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …
CVE-2026-88017High· 7.3rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the se…
CVE-2026-88012Medium· 5.3Traefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connectio…
CVE-2026-88044Critical· 9.1PoCrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…
CVE-2026-88015Medium· 5.3PoCrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.De…