Tagged “osv”
CVEs tagged osv, newest first.
5468 CVEsRSS
CVE-2026-93601Low· 2.2rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name…
CVE-2026-93599High· 7.5PoCrustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs
rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (ze…
CVE-2026-93602Medium· 4.4rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints
rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. At…
CVE-2026-93600Low· 2.2rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced
rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Becaus…
RUSTSEC-2026-0289Nonepqc_kyber is unmaintained
pqc_kyber is unmaintained
RUSTSEC-2026-0287Nonecosmian_kyber is unmaintained
cosmian_kyber is unmaintained
MAL-2026-16275Critical⚠ ExploitedMalicious code in requests-triwes (PyPI)
Malicious code in requests-triwes (PyPI)
MAL-2026-16274Critical⚠ ExploitedMalicious code in requests-auroras (PyPI)
Malicious code in requests-auroras (PyPI)
MAL-2026-16269Critical⚠ ExploitedMalicious code in requests-asetwe (PyPI)
Malicious code in requests-asetwe (PyPI)
MAL-2026-16268Critical⚠ ExploitedMalicious code in index-forum (PyPI)
Malicious code in index-forum (PyPI)
MAL-2026-16267Critical⚠ ExploitedMalicious code in pyjstat-smooth (PyPI)
Malicious code in pyjstat-smooth (PyPI)
MAL-2026-16264Critical⚠ ExploitedMalicious code in aiosendletter (PyPI)
Malicious code in aiosendletter (PyPI)
GHSA-xjw9-38cr-6372Highdjust: A template binding inherits a context safety grant it never earned (XSS)
djust: A template binding inherits a context safety grant it never earned (XSS)
GHSA-9395-2g46-rj3fHighdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
CVE-2026-86049High· 7.1Jupyter Server is the backend for Jupyter web applications
Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…
CVE-2026-77281Medium· 6.5Caddy is an extensible server platform that uses TLS by default
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…
CVE-2026-68537High· 7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…
CVE-2026-68523High· 7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…
CVE-2026-86000Medium· 5.3PoCSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and V…
CVE-2026-85999Medium· 5.3Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used …
MAL-2026-16250Critical⚠ ExploitedMalicious code in marketing-mcp (PyPI)
Malicious code in marketing-mcp (PyPI)
CVE-2026-85078Medium· 6.5Sanic is an opensource python web server/framework
Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer.…
GO-2026-6449NoneKomari: Management Interface CSRF in github.com/komari-monitor/komari
Komari: Management Interface CSRF in github.com/komari-monitor/komari
RUSTSEC-2026-0286NoneOut-of-bounds read when decoding CKA_ALLOWED_MECHANISMS
Out-of-bounds read when decoding CKA_ALLOWED_MECHANISMS
MAL-2026-16242Critical⚠ ExploitedMalicious code in trongappy (PyPI)
Malicious code in trongappy (PyPI)
MAL-2026-16241Critical⚠ ExploitedMalicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)
Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)
MAL-2026-16240Critical⚠ ExploitedMalicious code in praetorian-mind-rce-test-2026 (PyPI)
Malicious code in praetorian-mind-rce-test-2026 (PyPI)
CVE-2026-61599High· 8.8djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling …
CVE-2026-61589Medium· 6.3djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFac…
CVE-2026-64684Medium· 6.8RMCP is an official Rust SDK for the Model Context Protocol
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest…