VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-78676Critical· 9.8
1mo ago

gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlin…

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.78%via CSAF
CVE-2026-65087Medium· 6.1
1mo ago

NVIDIA NemoClaw contains a vulnerability where an attacker could cause

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.

▾ Sunlituff · uffEPSS 0.15%via OSV
CVE-2026-79674High· 7.5
1mo ago

nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)

A flaw was found in NLTK. A path traversal vulnerability in corpus-reader constructors allows a remote attacker to bypass the intended data root sandbox. By supplying arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.39%via CSAF
CVE-2026-78682High· 7.5
1mo ago

nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)

A flaw was found in NLTK. When an HTTP proxy is configured, a server-side request forgery (SSRF) vulnerability exists in the `nltk.pathsec.urlopen` function. An attacker can exploit this by providing a seemingly valid public URL, which the…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.43%via CSAF
CVE-2026-79675High· 8.1
1mo ago

nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options (CVE-2026-79675)

A flaw was found in NLTK. When processing untrusted input for its `per-call options` parameter in the `java()` function, NLTK fails to validate Java Virtual Machine (JVM) options. A remote attacker could exploit this by injecting dangerous…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.78%via CSAF
CVE-2026-78680High· 7.8
1mo ago

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary …

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary …

▾ Twilightnltk · nltkEPSS 0.18%via NVD
CVE-2026-79669Medium· 4.3
1mo ago

Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs

Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs. Attackers can access historical logs and real-time log streams via GET /api/system/logs, G…

▾ Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.21%via NVD
CVE-2026-79779Medium· 5.3
1mo ago

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker obse…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.15%via NVD
CVE-2026-79782Low· 3.1
1mo ago

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.23%via NVD
CVE-2026-79777Low· 2.7
1mo ago

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.33%via NVD
CVE-2026-79664High· 7.4
1mo ago

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on ni…

▾ Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.27%via NVD
CVE-2026-79783Low· 3.6
1mo ago

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservati…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.18%via NVD
CVE-2026-79781Medium· 6.5
1mo ago

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-sec…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.34%via NVD
CVE-2026-79780Medium· 5.3
1mo ago

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.13%via NVD
CVE-2026-79659High· 7.7
1mo ago

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbit…

▾ Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.26%via NVD
CVE-2026-79778Medium· 5.3
1mo ago

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connectio…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.32%via NVD
GO-2026-6289None
1mo ago

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

▾ Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GO-2026-6287None
1mo ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/…

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

▾ Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GO-2026-6278None
1mo ago

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket

▾ Sunlitgorilla · github.com/gorilla/websocketvia OSV
GO-2026-6277None
1mo ago

netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil

netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia OSV
GO-2026-6269None
1mo ago

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via OSV
GO-2026-6268None
1mo ago

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via OSV
GO-2026-6267None
1mo ago

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

▾ Sunlitcoder · github.com/coder/codervia OSV
GO-2026-6265None
1mo ago

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

▾ Sunlitcoder · github.com/coder/codervia OSV
GO-2026-6262None
1mo ago

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu

▾ Sunlitopentofu · github.com/opentofu/opentofuvia OSV
MAL-2026-14516None
1mo ago

Malicious code in minecraft-ytreceiver (PyPI)

Malicious code in minecraft-ytreceiver (PyPI)

▾ Sunlitminecraft-ytreceiver · minecraft-ytreceivervia OSV
MAL-2026-14488None
1mo ago

Malicious code in python-walletlibr-v (PyPI)

Malicious code in python-walletlibr-v (PyPI)

▾ Sunlitpython-walletlibr-v · python-walletlibr-vvia OSV
CVE-2026-45018Critical· 9.8
1mo ago

Chainlit is a Python framework for building production-ready conversational AI applications

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…

▾ Midnightchainlit · chainlitEPSS 1.1%via NVD
CVE-2026-45019High· 7.2
1mo ago

Chainlit is a Python framework for building production-ready conversational AI applications

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…

▾ Twilightchainlit · chainlitEPSS 0.43%via NVD
CVE-2026-55099High· 7.5
1mo ago

icalendar has Algorithmic Complexity in Equality

icalendar has Algorithmic Complexity in Equality

▾ Twilighticalendar · icalendarEPSS 0.63%via OSV
CVEs tagged “osv” — page 20 · VulnSea