Tagged “osv”
CVEs tagged osv, newest first.
5670 CVEsRSS
CVE-2026-87817High· 8.8GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a ma…
CVE-2026-87819High· 7.5GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containi…
GHSA-57v5-wqx3-cgj4Medium· 5.8SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAt…
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
CVE-2026-72790Medium· 5.8SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /ap…
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
CVE-2026-12259Medium· 5.3NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
CVE-2026-78675High· 8.4⚖ disputedGitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
CVE-2026-80206HighNLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
CVE-2026-78681HighNLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
CVE-2026-79676HighNLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
CVE-2026-79657CriticalNLTK: Allowlisted pickle loaders still permit code execution in current source
NLTK: Allowlisted pickle loaders still permit code execution in current source
CVE-2026-78683CriticalNLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
MAL-2026-16017Critical⚠ ExploitedMalicious code in telegram-helper (PyPI)
Malicious code in telegram-helper (PyPI)
MAL-2026-16016Critical⚠ ExploitedMalicious code in cv-train (PyPI)
Malicious code in cv-train (PyPI)
RUSTSEC-2026-0281None`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code
`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code
RUSTSEC-2026-0280None`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code
`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code
CVE-2026-86257Medium· 5.4PoC⚖ disputedwger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas
wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or ex…
CVE-2026-86256Medium· 5.4PoCwger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)
wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET param…
CVE-2026-86255Medium· 6.5wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods
wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endp…
MAL-2026-15938Critical⚠ ExploitedMalicious code in dac-tools (PyPI)
Malicious code in dac-tools (PyPI)
MAL-2026-15937NoneMalicious code in minecraftmodes (PyPI)
Malicious code in minecraftmodes (PyPI)
MAL-2026-15936NoneMalicious code in trongridew (PyPI)
Malicious code in trongridew (PyPI)
MAL-2026-15935Critical⚠ ExploitedMalicious code in proxycer (PyPI)
Malicious code in proxycer (PyPI)
MAL-2026-15934NoneMalicious code in dbt-sa-cli (PyPI)
Malicious code in dbt-sa-cli (PyPI)
RUSTSEC-2026-0292NoneDouble free / use-after-free in `Chunk` and `InlineArray` removal methods when an element's `Drop` panics
Double free / use-after-free in `Chunk` and `InlineArray` removal methods when an element's `Drop` panics
MAL-2026-16044Critical⚠ ExploitedMalicious code in tsshare (PyPI)
Malicious code in tsshare (PyPI)
CVE-2026-63464High· 7.7PoCnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/w…
MAL-2026-15933NoneMalicious code in houdus (PyPI)
Malicious code in houdus (PyPI)
MAL-2026-15932NoneMalicious code in chartkit-core (PyPI)
Malicious code in chartkit-core (PyPI)
CVE-2026-72799Medium· 5.8SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
CVE-2026-72794High· 8.6SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf