Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
MAL-2026-14341NoneMalicious code in reqcrypts (PyPI)
Malicious code in reqcrypts (PyPI)
CVE-2026-43980Medium· 6.3Malla is a web analyzer for Meshtastic networks based on MQTT data
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered int…
CVE-2026-53572Medium· 5.9KEDA is a Kubernetes-based Event Driven Autoscaling component
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values,…
CVE-2026-71485Critical· 9.1Centrifugo is an open-source scalable real-time messaging server
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers,…
CVE-2026-61625Medium· 6.8VictoriaMetrics is a scalable solution for monitoring and managing time series data
VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/bac…
CVE-2026-71428Critical· 9.3The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…
CVE-2026-67446Medium· 5.3⚖ disputedMailpit is an email testing tool and API for developers
Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded dimensions, pixel count, or memory use in the GET /api/v1/message/{i…
CVE-2026-72818High· 7.5PoCThe URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Inpu…
CVE-2026-71492Medium· 6.5Banks generates meaningful LLM prompts using a simple template language
Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values in…
RUSTSEC-2026-0269NoneFilesystem sandbox escape when paths or symlinks contain trailing slashes
Filesystem sandbox escape when paths or symlinks contain trailing slashes
RUSTSEC-2026-0268NoneGuest controlled-size host heap allocation through WASIp3 streams
Guest controlled-size host heap allocation through WASIp3 streams
CVE-2026-55558Medium· 5.9aiosmtplib is an asynchronous SMTP client for use with asyncio
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. A…
CVE-2026-54770Medium· 6.1WebOb provides objects for HTTP requests and responses
WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips le…
CVE-2026-54623High· 7.1django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value with…
CVE-2026-54625Medium· 4.8django CMS is a content management system powered by Django
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key funct…
MAL-2026-14340NoneMalicious code in tinymember (crates.io)
Malicious code in tinymember (crates.io)
MAL-2026-14339NoneMalicious code in proc_macro_en (crates.io)
Malicious code in proc_macro_en (crates.io)
MAL-2026-14338NoneMalicious code in proc_macro1 (crates.io)
Malicious code in proc_macro1 (crates.io)
MAL-2026-14337NoneMalicious code in internment (crates.io)
Malicious code in internment (crates.io)
MAL-2026-14336NoneMalicious code in arrayref (crates.io)
Malicious code in arrayref (crates.io)
MAL-2026-14335NoneMalicious code in aronenao (crates.io)
Malicious code in aronenao (crates.io)
MAL-2026-14334NoneMalicious code in arone (crates.io)
Malicious code in arone (crates.io)
MAL-2026-14333NoneMalicious code in append_only_vec (crates.io)
Malicious code in append_only_vec (crates.io)
MAL-2026-14332NoneMalicious code in aovine (crates.io)
Malicious code in aovine (crates.io)
RUSTSEC-2026-0266None`internment` 0.8.7 was removed from crates.io due to a malicious dependency
`internment` 0.8.7 was removed from crates.io due to a malicious dependency
RUSTSEC-2026-0265None`proc-macro1` was removed from crates.io due to malicious code
`proc-macro1` was removed from crates.io due to malicious code
RUSTSEC-2026-0264None`proc-macro-en` was removed from crates.io due to malicious code
`proc-macro-en` was removed from crates.io due to malicious code
RUSTSEC-2026-0263None`tinymember` was removed from crates.io due to affiliation with malicious code
`tinymember` was removed from crates.io due to affiliation with malicious code
RUSTSEC-2026-0262None`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
RUSTSEC-2026-0261None`aronenao` was removed from crates.io due to malicious code
`aronenao` was removed from crates.io due to malicious code