VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-74887Medium· 5.9
1mo ago

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/mod…

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is …

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.30%via OSV
CVE-2026-74882Critical· 9.1
1mo ago

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in …

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate hea…

▾ Midnightopenssl-encrypt · openssl-encryptEPSS 0.17%via OSV
CVE-2026-74899None
1mo ago

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects i…

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro_…

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.75%via OSV
RUSTSEC-2026-0258None
1mo ago

h2 unbounded empty DATA frames

h2 unbounded empty DATA frames

▾ Sunlith2 · h2via OSV
MAL-2026-14100None
1mo ago

Malicious code in socks5901 (PyPI)

Malicious code in socks5901 (PyPI)

▾ Sunlitsocks5901 · socks5901via OSV
CVE-2026-74881Medium· 6.5⚖ disputed
1mo ago

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of …

▾ Sunlitjahlives · openssl_encryptEPSS 0.36%via NVD
CVE-2026-59894Medium
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the correspond…

▾ Sunlitsqlparse · sqlparseEPSS 0.18%via NVD
CVE-2026-71491High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption t…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.26%via NVD
CVE-2026-54284High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing …

▾ Twilightsqlparse · sqlparseEPSS 0.33%via NVD
CVE-2026-59893High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters,…

▾ Twilightsqlparse · sqlparseEPSS 0.34%via NVD
CVE-2026-46345High· 8.4
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does …

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.20%via NVD
RUSTSEC-2026-0290High· 7.4
1mo ago

pqc_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery

pqc_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery

▾ Twilightpqc_kyber · pqc_kybervia OSV
RUSTSEC-2026-0288High· 7.4
1mo ago

cosmian_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery

cosmian_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery

▾ Twilightcosmian_kyber · cosmian_kybervia OSV
CVE-2024-58375High· 7.5⚖ disputed
1mo ago

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive m…

▾ Twilightopentofu · github.com/opentofu/opentofuEPSS 0.43%via NVD
CVE-2026-74796Medium· 6.1
1mo ago

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package content…

▾ Sunlitopentofu · github.com/opentofu/opentofuEPSS 0.34%via NVD
CVE-2026-74797Low· 3.1
1mo ago

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling …

▾ Sunlitopentofu · github.com/opentofu/opentofuEPSS 0.28%via NVD
MAL-2026-14069None
1mo ago

Malicious code in kb-ai (PyPI)

Malicious code in kb-ai (PyPI)

▾ Sunlitkb-ai · kb-aivia OSV
RUSTSEC-2026-0275Medium· 6.5
1mo ago

Legacy `azure_core` writes the `authorization` header value to logs

Legacy `azure_core` writes the `authorization` header value to logs

▾ Sunlitazure_core · azure_corevia OSV
CVE-2026-63740Medium· 6.5
1mo ago

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

▾ Sunlitsurrealdb · surrealdbEPSS 0.36%via OSV
CVE-2026-73051Medium
1mo ago

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit …

▾ Sunlitactix-http · actix-httpEPSS 0.57%via NVD
CVE-2026-72813High· 7.5
1mo ago

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET reque…

▾ TwilightRed Hat · Red Hat OpenShift Update ServiceEPSS 0.49%via NVD
CVE-2026-72814Medium· 5.3
1mo ago

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the serv…

▾ SunlitRed Hat · Red Hat OpenShift Update ServiceEPSS 0.47%via NVD
CVE-2025-71405Medium
1mo ago

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary ho…

▾ Sunlitgo-chi · github.com/go-chi/chi/v5EPSS 0.39%via NVD
CVE-2026-72816Medium· 6.5
1mo ago

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.Remot…

▾ Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.30%via NVD
CVE-2026-72817Medium· 6.5
1mo ago

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

▾ Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.24%via NVD
CVE-2026-72815Medium· 6.5PoC
1mo ago

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access…

▾ Twilightgo-chi · github.com/go-chi/chi/v5/middlewareEPSS 0.50%via NVD
CVE-2026-46603High· 7.5
1mo ago

golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation (CVE-2026-46603)

A flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a denial of service by providing a specially crafted VP8L image. This image, containing many unused Huffman tree groups, leads to excessive memory allocation during V…

▾ TwilightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.16EPSS 0.75%via CSAF
CVE-2026-46380Medium· 6.7
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an at…

▾ Sunlitcompliance-trestle · compliance-trestleEPSS 0.14%via NVD
CVE-2026-47191Low
1mo ago

kas is a setup tool for bitbake based projects

kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a…

▾ Sunlitkas · kasEPSS 0.25%via NVD
CVE-2026-46439High· 7.8
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.27%via NVD
CVEs tagged “osv” — page 27 · VulnSea