Tagged “osv”
CVEs tagged osv, newest first.
5670 CVEsRSS
MAL-2026-15931Critical⚠ ExploitedMalicious code in metricboxlite (PyPI)
Malicious code in metricboxlite (PyPI)
MAL-2026-15930NoneMalicious code in tpu-raiden-jax (PyPI)
Malicious code in tpu-raiden-jax (PyPI)
MAL-2026-15929NoneMalicious code in pymaas (PyPI)
Malicious code in pymaas (PyPI)
MAL-2026-15928NoneMalicious code in olympuslib (PyPI)
Malicious code in olympuslib (PyPI)
MAL-2026-15927NoneMalicious code in qoeoe (PyPI)
Malicious code in qoeoe (PyPI)
MAL-2026-15926NoneMalicious code in astlsi (PyPI)
Malicious code in astlsi (PyPI)
MAL-2026-15910NoneMalicious code in timeweave (PyPI)
Malicious code in timeweave (PyPI)
CVE-2026-68584High· 8.6SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
MAL-2026-15864Critical⚠ ExploitedMalicious code in asti (PyPI)
Malicious code in asti (PyPI)
CVE-2026-72806Medium· 5.8SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents with…
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
CVE-2026-72800Medium· 5.8SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeratio…
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
CVE-2026-68587High· 8.6SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rende…
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
CVE-2026-68586High· 8.6SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-f…
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
CVE-2026-69086High· 7.7SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclo…
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
CVE-2026-65607Medium· 6.5SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
CVE-2026-66394High· 8.7SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
MAL-2026-15863NoneMalicious code in uvhttp-custom (PyPI)
Malicious code in uvhttp-custom (PyPI)
MAL-2026-15862NoneMalicious code in py-2equests (PyPI)
Malicious code in py-2equests (PyPI)
MAL-2026-15861NoneMalicious code in py-1requests (PyPI)
Malicious code in py-1requests (PyPI)
MAL-2026-15860NoneMalicious code in py-0requests (PyPI)
Malicious code in py-0requests (PyPI)
MAL-2026-15859NoneMalicious code in 0requests (PyPI)
Malicious code in 0requests (PyPI)
MAL-2026-15858NoneMalicious code in trongridi (PyPI)
Malicious code in trongridi (PyPI)
MAL-2026-15829NoneMalicious code in telemetry-helper (PyPI)
Malicious code in telemetry-helper (PyPI)
MAL-2026-15828NoneMalicious code in env-validator-tool (PyPI)
Malicious code in env-validator-tool (PyPI)
MAL-2026-15827NoneMalicious code in company-sdk (PyPI)
Malicious code in company-sdk (PyPI)
RUSTSEC-2026-0300NoneUse-after-free in `clear` and `retain` when an element's `Drop` panics
Use-after-free in `clear` and `retain` when an element's `Drop` panics
CVE-2026-84452HighWindows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML
Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API…
CVE-2026-84382High· 7.5HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bo…
CVE-2026-84380Medium· 5.6HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding h…
CVE-2026-84379Medium· 5.3HTTPX2 is a next generation HTTP client for Python
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-ele…