VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-47192Low
1mo ago

kas is a setup tool for bitbake based projects

kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may a…

▾ Sunlitkas · kasEPSS 0.25%via NVD
CVE-2026-19730Medium· 4.2PoC
1mo ago

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL defau…

▾ TwilightRed Hat · podmanEPSS 0.16%via NVD
CVE-2026-73558Medium· 5.3
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a reque…

▾ Sunlitvllm · vllmEPSS 0.41%via NVD
CVE-2026-73555Medium· 5.3
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_m…

▾ Sunlitvllm · vllmEPSS 0.42%via NVD
CVE-2026-73556Medium· 5.3⚖ disputed
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compi…

▾ Sunlitvllm · vllmEPSS 0.52%via NVD
CVE-2026-73557Medium
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable,…

▾ Sunlitvllm · vllmEPSS 0.40%via NVD
CVE-2026-73841High· 8.8
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:vi…

▾ Twilightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.81%via NVD
CVE-2026-73667High· 8.8
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workf…

▾ Twilightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.86%via NVD
CVE-2026-56860High· 7.5
1mo ago

Avoid quadratic complexity in resolvePath in net/url

Avoid quadratic complexity in resolvePath in net/url

▾ Twilightstdlib · stdlibEPSS 0.55%via OSV
CVE-2026-56864High· 8.1
1mo ago

golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB (CVE-2026-56864)

A flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver mal…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security for Kubernetes 4.11EPSS 0.32%via CSAF
CVE-2026-56865High· 8.8
1mo ago

golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass (CVE-2026-5…

A flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go mod…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security for Kubernetes 4.11EPSS 0.14%via CSAF
CVE-2026-56858High· 8.1
1mo ago

Fix Javascript regexp context tracking in html/template

Fix Javascript regexp context tracking in html/template

▾ Twilightstdlib · stdlibEPSS 0.31%via OSV
CVE-2026-56862High· 7.5
1mo ago

Limit handshake messages we are willing to accept post-handshake in crypto/tls

Limit handshake messages we are willing to accept post-handshake in crypto/tls

▾ Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-56853High· 7.5
1mo ago

net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)

A flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTi…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.22EPSS 0.57%via CSAF
CVE-2026-56859High· 7.5
1mo ago

Add recursion depth guard during decode in encoding/xml

Add recursion depth guard during decode in encoding/xml

▾ Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-33818High· 7.5
1mo ago

Enforce maximum recursion depth in encoding/asn1

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

▾ TwilightGo standard library · encoding/asn1EPSS 0.57%via CVEORG
CVE-2026-73626High· 7.5⚖ disputed
1mo ago

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install()

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/bloc…

▾ Twilightjupyterlab · jupyterlabEPSS 0.36%via NVD
CVE-2026-73625High· 8.8
1mo ago

gitpython: GitPython: Remote Code Execution via kwarg value smuggling (CVE-2026-73625)

A flaw was found in GitPython. Attackers can bypass the `check_unsafe_options` guard by smuggling git options within single-character keyword argument (kwarg) values. This allows them to supply specially crafted option dictionaries to vari…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.92%via CSAF
CVE-2026-73624High· 8.1
1mo ago

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter o…

▾ Twilightgitpython_project · gitpythonEPSS 0.55%via NVD
CVE-2026-73623High· 7.5
1mo ago

gitpython: GitPython: Remote Code Execution via malicious Git template (CVE-2026-73623)

A flaw was found in GitPython. An incomplete denylist in the `unsafe_git_clone_options` function fails to restrict the `--template` option. This allows a remote attacker to supply a malicious Git template directory, leading to arbitrary co…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.83%via CSAF
CVE-2026-73620High· 8.8
1mo ago

gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620)

A flaw was found in GitPython. This vulnerability arises from insufficient guarding of git option forwarding within the `IndexFile.checkout()` and `TagReference.create()` functions. An authenticated attacker can exploit this by passing uns…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.57%via CSAF
CVE-2026-73489Medium· 4.3
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than 130 terminal-mode records. The parser in russh/src/server/encrypt…

▾ Sunlitrussh · russhEPSS 0.45%via NVD
CVE-2026-73506Medium· 6.1
1mo ago

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Su…

▾ Sunlitjandedobbeleer · github.com/jandedobbeleer/oh-my-poshEPSS 0.18%via NVD
CVE-2026-73509High· 7.6
1mo ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and valid…

▾ TwilightOpenListTeam · github.com/OpenListTeam/OpenList/v4EPSS 0.52%via NVD
CVE-2026-73505High· 7.8
1mo ago

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose functi…

▾ Twilightjandedobbeleer · github.com/jandedobbeleer/oh-my-poshEPSS 0.21%via NVD
CVE-2026-73564High
1mo ago

frp is a fast reverse proxy

frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF ma…

▾ Twilightfatedier · github.com/fatedier/frpEPSS 0.52%via NVD
CVE-2026-73417High· 8.3
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an ov…

▾ Twilightjupyterlab · jupyterlabEPSS 0.75%via NVD
CVE-2026-73568High· 7.5
1mo ago

py-libp2p is the Python implementation of the libp2p networking stack

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly…

▾ Twilightlibp2p · libp2pEPSS 0.49%via NVD
CVE-2026-73416Medium
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, Jup…

▾ Sunlitjupyterlab · jupyterlabEPSS 0.66%via NVD
CVE-2026-73652High
1mo ago

vantage6 is an open-source infrastructure for privacy preserving analysis

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorith…

▾ Twilightvantage6 · vantage6EPSS 0.35%via NVD
CVEs tagged “osv” — page 28 · VulnSea