VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

RUSTSEC-2026-0267None
1mo ago

Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)

Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)

▾ Sunlitstable-vec · stable-vecvia OSV
MAL-2026-14444None
1mo ago

Malicious code in msrcpoc (PyPI)

Malicious code in msrcpoc (PyPI)

▾ Sunlitmsrcpoc · msrcpocvia OSV
MAL-2026-14401None
1mo ago

Malicious code in multyproccess (PyPI)

Malicious code in multyproccess (PyPI)

▾ Sunlitmultyproccess · multyproccessvia OSV
CVE-2026-45404Medium
1mo ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe fo…

▾ Sunlitotel · go.opentelemetry.io/otel/bridge/opentracingEPSS 0.14%via NVD
MAL-2026-14389None
1mo ago

Malicious code in envprovision (PyPI)

Malicious code in envprovision (PyPI)

▾ Sunlitenvprovision · envprovisionvia OSV
MAL-2026-14388None
1mo ago

Malicious code in cryptgraphy (PyPI)

Malicious code in cryptgraphy (PyPI)

▾ Sunlitcryptgraphy · cryptgraphyvia OSV
MAL-2026-14384None
1mo ago

Malicious code in mlflow-otel-instrumentor (PyPI)

Malicious code in mlflow-otel-instrumentor (PyPI)

▾ Sunlitmlflow-otel-instrumentor · mlflow-otel-instrumentorvia OSV
CVE-2026-70626Medium· 6.2
1mo ago

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does no…

▾ Sunlitnltk · nltkEPSS 0.20%via NVD
CVE-2026-66393High· 7.5
1mo ago

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exce…

▾ Twilightnltk · nltkEPSS 0.52%via NVD
CVE-2026-65915Medium· 6.5
1mo ago

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to…

▾ Sunlitnltk · nltkEPSS 0.41%via NVD
CVE-2026-63312High· 7.5
1mo ago

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open()

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can r…

▾ Twilightnltk · nltkEPSS 0.65%via NVD
CVE-2026-62385Medium· 5.9
1mo ago

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attac…

▾ Sunlitnltk · nltkEPSS 0.42%via NVD
CVE-2026-62384High· 7.5
1mo ago

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators i…

▾ Twilightnltk · nltkEPSS 0.65%via NVD
CVE-2026-62383Medium· 5.5
1mo ago

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitra…

▾ Sunlitnltk · nltkEPSS 0.18%via NVD
CVE-2026-71514Low· 2.5
1mo ago

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result w…

▾ Sunlitnltk · nltkEPSS 0.17%via NVD
CVE-2026-71513High· 8.8
1mo ago

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables …

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables …

▾ Twilightnltk · nltkEPSS 1.1%via NVD
MAL-2026-14358None
1mo ago

Malicious code in scrambleeeer (PyPI)

Malicious code in scrambleeeer (PyPI)

▾ Sunlitscrambleeeer · scrambleeeervia OSV
CVE-2026-71494Medium
1mo ago

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a…

▾ Sunlitinfracost · github.com/infracost/infracostEPSS 0.50%via NVD
CVE-2026-71493Medium
1mo ago

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go use a lexical filepath.Rel …

▾ Sunlitinfracost · github.com/infracost/infracostEPSS 0.54%via NVD
CVE-2026-62675High· 8.8
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle…

▾ Twilightomnigent · omnigentEPSS 0.65%via NVD
CVE-2026-62674Critical· 9.0
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template ag…

▾ Midnightomnigent · omnigentEPSS 0.51%via NVD
CVE-2026-62677High· 8.8
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value beca…

▾ Twilightomnigent · omnigentEPSS 0.61%via NVD
CVE-2026-62676High· 7.1
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the ti…

▾ Twilightomnigent · omnigentEPSS 0.40%via NVD
CVE-2026-62283Critical· 9.9
1mo ago

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_strea…

▾ Midnightnezhahq · github.com/nezhahq/nezhaEPSS 0.55%via NVD
CVE-2026-49114High· 7.1
1mo ago

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. …

▾ Twilightlinuxfoundation · onnxEPSS 0.16%via NVD
CVE-2026-61539Critical· 10.0
1mo ago

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

▾ Midnightxinference · xinferenceEPSS 1.2%via OSV
CVE-2026-68508High· 7.8
1mo ago

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instanti…

▾ Twilighthydra-core · hydra-coreEPSS 0.46%via NVD
MAL-2026-14351None
1mo ago

Malicious code in requests-crypt (PyPI)

Malicious code in requests-crypt (PyPI)

▾ Sunlitrequests-crypt · requests-cryptvia OSV
MAL-2026-14350None
1mo ago

Malicious code in scrambleeer (PyPI)

Malicious code in scrambleeer (PyPI)

▾ Sunlitscrambleeer · scrambleeervia OSV
MAL-2026-14349None
1mo ago

Malicious code in boto4 (PyPI)

Malicious code in boto4 (PyPI)

▾ Sunlitboto4 · boto4via OSV
CVEs tagged “osv” — page 22 · VulnSea