Tagged “osv”
CVEs tagged osv, newest first.
5666 CVEsRSS
MAL-2026-15578NoneMalicious code in trongridor (PyPI)
Malicious code in trongridor (PyPI)
MAL-2026-15577NoneMalicious code in auth-app-streamlit (PyPI)
Malicious code in auth-app-streamlit (PyPI)
MAL-2026-15566NoneMalicious code in flask-header-guard (PyPI)
Malicious code in flask-header-guard (PyPI)
CVE-2026-82250Medium· 6.5gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
MAL-2026-15488NoneMalicious code in calcboxlite (PyPI)
Malicious code in calcboxlite (PyPI)
CVE-2026-55830High· 8.3RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments
CVE-2026-56854Medium· 6.8golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854)
A flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the Se…
MAL-2026-14590NoneMalicious code in yamlformatter-utils (PyPI)
Malicious code in yamlformatter-utils (PyPI)
MAL-2026-14589NoneMalicious code in yamlformat-tools (PyPI)
Malicious code in yamlformat-tools (PyPI)
MAL-2026-14588NoneMalicious code in yaml-report-formatter (PyPI)
Malicious code in yaml-report-formatter (PyPI)
MAL-2026-14587NoneMalicious code in pygame-renderkit (PyPI)
Malicious code in pygame-renderkit (PyPI)
CVE-2026-55248Critical· 9.1plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone.app.portlets vulnerable to denial of service via RSS feed portlet
CVE-2026-55520HighProtego has exponential backtracking ReDoS in robots.txt URL wildcard matching
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-55247Critical· 9.1plone.app.event vulnerable to denial of service via iCalendar import
plone.app.event vulnerable to denial of service via iCalendar import
CVE-2026-55509HighWsgiDAV MySQL provider has a blind SQL injection
WsgiDAV MySQL provider has a blind SQL injection
CVE-2026-55485High· 8.8piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
CVE-2026-55108High· 8.5KubeVela is an open source application delivery platform
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, G…
CVE-2026-54757High· 7.8Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
CVE-2026-81702Noneopenssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers …
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with thei…
CVE-2026-81694Noneopenssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenti…
openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filen…
CVE-2026-81689Noneopenssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allow…
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can pre…
CVE-2026-81680Medium· 5.3openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers …
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to …
CVE-2026-37004Critical· 9.8LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
CVE-2026-81721Noneopenssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to…
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitr…
CVE-2026-81719Noneopenssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to …
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process …
CVE-2026-81717Noneopenssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model …
openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._veri…
CVE-2026-81716Noneopenssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authoriz…
openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permissio…
CVE-2026-81714Noneopenssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plug…
openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unkn…