Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
MAL-2026-14584NoneMalicious code in flyteplugins-redis (PyPI)
Malicious code in flyteplugins-redis (PyPI)
MAL-2026-14583NoneMalicious code in flyteplugins-nsight (PyPI)
Malicious code in flyteplugins-nsight (PyPI)
MAL-2026-14582NoneMalicious code in flyteplugins-echo (PyPI)
Malicious code in flyteplugins-echo (PyPI)
MAL-2026-14581NoneMalicious code in flyteplugins-agento11y (PyPI)
Malicious code in flyteplugins-agento11y (PyPI)
MAL-2026-14556NoneMalicious code in sap-quarterly-report (PyPI)
Malicious code in sap-quarterly-report (PyPI)
MAL-2026-14555NoneMalicious code in ekx-report-utils (PyPI)
Malicious code in ekx-report-utils (PyPI)
MAL-2026-14554NoneMalicious code in decoris (PyPI)
Malicious code in decoris (PyPI)
MAL-2026-14552NoneMalicious code in mathkitlite (PyPI)
Malicious code in mathkitlite (PyPI)
GHSA-mf7q-r4rv-jv94HighCrossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
RUSTSEC-2026-0284NoneDouble free in `Map::into_iter` and an uninitialized `Arc` in `SharedIncin::clear`
Double free in `Map::into_iter` and an uninitialized `Arc` in `SharedIncin::clear`
CVE-2026-57171High· 7.7Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author comma…
RUSTSEC-2026-0277NonePath traversal in apimock-server's file-serving fallback
Path traversal in apimock-server's file-serving fallback
RUSTSEC-2026-0276NonePath traversal in apimock's file-serving fallback
Path traversal in apimock's file-serving fallback
CVE-2026-80205High· 7.5nltk: NLTK: Denial of Service via unvalidated regular expressions (CVE-2026-80205)
A flaw was found in NLTK. A remote attacker can exploit a regular expression denial of service (ReDoS) vulnerability in the `Text.findall()` and `TokenSearcher.findall()` methods. These methods accept user-supplied regular expressions with…
CVE-2026-79921High· 7.5amqp091-go is a Go AMQP 0.9.1 client
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead …
CVE-2026-57170High· 7.8Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-par…
MAL-2026-14545Critical⚠ ExploitedMalicious code in pybitjs (PyPI)
Malicious code in pybitjs (PyPI)
MAL-2026-14542NoneMalicious code in trongridet (PyPI)
Malicious code in trongridet (PyPI)
MAL-2026-14525NoneMalicious code in 0xfighter3 (PyPI)
Malicious code in 0xfighter3 (PyPI)
MAL-2026-14524NoneMalicious code in bigquery-agent-analytics-tracing (PyPI)
Malicious code in bigquery-agent-analytics-tracing (PyPI)
MAL-2026-14523NoneMalicious code in rce-test (PyPI)
Malicious code in rce-test (PyPI)
MAL-2026-14522NoneMalicious code in syntaxerror-package-12345 (PyPI)
Malicious code in syntaxerror-package-12345 (PyPI)
CVE-2026-54569Critical· 9.8senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite.core Vulnerable to Eval Injection and Missing Authorization
CVE-2026-54590Medium· 5.9asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakl…
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
CVE-2026-54591High· 8.1asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh has SCP Path Traversal to Arbitrary File Write
CVE-2026-54553Medium· 5.4Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
CVE-2026-54548Low· 3.3kas Persistently Disables SSH Host Key Checking
kas Persistently Disables SSH Host Key Checking
CVE-2026-78679Medium· 6.5GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arb…
CVE-2026-78678Medium· 6.5gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)
A flaw was found in GitPython. An incomplete denylist in the `unsafe_git_revision_options` guard omits `--contents` and `-S` options. This allows an attacker to read arbitrary files by passing these options to the `Repo.blame()` function. …
CVE-2026-78677High· 7.5GitPython: GitPython: Arbitrary Code Execution via Path Traversal (CVE-2026-78677)
A flaw was found in GitPython. This vulnerability allows a remote attacker to create arbitrary Git directories outside the intended clone destination. By manipulating the `separate_git_dir` parameter during repository cloning, an attacker …