Tagged “osv”
CVEs tagged osv, newest first.
5670 CVEsRSS
CVE-2026-88013Low· 3.7PoCrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backen…
CVE-2026-88045High· 7.5PoCrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentL…
CVE-2026-88016High· 7.1PoCrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and l…
CVE-2026-88009High· 8.2Traefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path eval…
CVE-2026-88004High· 7.4Traefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing a…
MAL-2026-16125Critical⚠ ExploitedMalicious code in lucy-python-script-2030 (PyPI)
Malicious code in lucy-python-script-2030 (PyPI)
MAL-2026-16122Critical⚠ ExploitedMalicious code in pylever (PyPI)
Malicious code in pylever (PyPI)
CVE-2026-88014Medium· 6.3rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts archive/zip.File.N…
CVE-2026-88008Critical· 9.1PoC⚖ disputedTraefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backen…
CVE-2026-88011High· 8.1⚖ disputedTraefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy …
CVE-2026-88007Critical· 9.1Traefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport …
RUSTSEC-2026-0297None`unzip`: archive extraction is vulnerable to path traversal (zip-slip)
`unzip`: archive extraction is vulnerable to path traversal (zip-slip)
RUSTSEC-2026-0291NoneDouble free in `OwnedAlloc::drop_in_place` when the contained value's `Drop` panics
Double free in `OwnedAlloc::drop_in_place` when the contained value's `Drop` panics
MAL-2026-16121Critical⚠ ExploitedMalicious code in websetup (PyPI)
Malicious code in websetup (PyPI)
CVE-2026-59177High· 8.8PoCESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
CVE-2026-87012Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the share…
CVE-2026-87014Medium· 6.5PoCOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's d…
CVE-2026-87818Medium· 6.5PoCGitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create…
RUSTSEC-2026-0282NoneDouble free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
GO-2026-6302NoneSignature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
MAL-2026-16099Critical⚠ ExploitedMalicious code in bq-sdist-probe-vrp (PyPI)
Malicious code in bq-sdist-probe-vrp (PyPI)
MAL-2026-16098Critical⚠ ExploitedMalicious code in bq-build-probe-vrp-2026 (PyPI)
Malicious code in bq-build-probe-vrp-2026 (PyPI)
MAL-2026-16080Critical⚠ ExploitedMalicious code in databricks-webapp-navigation-homepage (PyPI)
Malicious code in databricks-webapp-navigation-homepage (PyPI)
GHSA-hxjg-93wc-h8p8High· 8.8Komari: Management Interface CSRF
Komari: Management Interface CSRF
CVE-2026-59185High· 8.5Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
CVE-2026-59172High· 7.8Joker linter executed project-local .jokerd/linter.* files during linting
Joker linter executed project-local .jokerd/linter.* files during linting
CVE-2026-87996High· 7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then l…
CVE-2025-24979Medium· 5.5LF Edge eKuiper: SSRF in External Service
LF Edge eKuiper: SSRF in External Service
CVE-2025-24978Low· 3.7LF Edge eKuiper: Self-XSS in External Service Creation
LF Edge eKuiper: Self-XSS in External Service Creation
CVE-2025-58363Medium· 5.5LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint