Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-53951HighCopier has a trust-prefix bypass via path traversal that runs tasks unprompted
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
CVE-2026-53964High· 7.2Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
MAL-2026-14274NoneMalicious code in reqcrypt-dev (PyPI)
Malicious code in reqcrypt-dev (PyPI)
RUSTSEC-2026-0271NoneFTP command injection via CRLF in control channel arguments
FTP command injection via CRLF in control channel arguments
GO-2026-6225NoneCredential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
GO-2026-6216NoneCross-forge account takeover on login in codefloe.com/crowci/crow/v6
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6
GO-2026-4950NoneAuthorization bypass via double-encoded paths in github.com/valyala/fasthttp
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp
CVE-2026-65959Medium· 5.3Vitess is a database clustering system for horizontal scaling of MySQL
Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() wi…
MAL-2026-14158NoneMalicious code in deepface-weight (PyPI)
Malicious code in deepface-weight (PyPI)
MAL-2026-14133NoneMalicious code in reqcrypt (PyPI)
Malicious code in reqcrypt (PyPI)
MAL-2026-14132NoneMalicious code in deepface-weights (PyPI)
Malicious code in deepface-weights (PyPI)
MAL-2026-14131NoneMalicious code in infogram-bot (PyPI)
Malicious code in infogram-bot (PyPI)
MAL-2026-14130NoneMalicious code in httpz-requests (PyPI)
Malicious code in httpz-requests (PyPI)
GO-2026-6246Noneuniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
GO-2026-6237NoneDenial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp
Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp
GO-2026-6197NoneWebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
GO-2026-6196NoneS3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
GO-2026-6190NoneUnsafe file permission restoration from metadata in github.com/rclone/rclone
Unsafe file permission restoration from metadata in github.com/rclone/rclone
GO-2026-6189NonePath traversal in serve s3 in github.com/rclone/rclone
Path traversal in serve s3 in github.com/rclone/rclone
GO-2026-6188NoneS3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
GO-2026-6183NoneNil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
GO-2026-6181NoneVerbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
CVE-2026-56874NonePre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
CVE-2026-56873NoneBackend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
Backend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
CVE-2026-56872NoneMalformed RowDescription and DataRow messages cause panics in github.com/lib/pq
Malformed RowDescription and DataRow messages cause panics in github.com/lib/pq
CVE-2026-56871NoneMalformed backend frame length causes panic in github.com/lib/pq
Malformed backend frame length causes panic in github.com/lib/pq
CVE-2026-56870NoneDisclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
Disclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
CVE-2026-56869NoneUnbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
Unbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
CVE-2026-56868NoneGSS authentication completes without mutual proof in github.com/lib/pq
GSS authentication completes without mutual proof in github.com/lib/pq
GO-2026-6143Nonenetfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil