VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-73559Medium· 6.5
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list…

▾ Sunlitvllm · vllmEPSS 0.58%via NVD
CVE-2026-54526High
1mo ago

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.55%via GHSA
CVE-2026-45774Medium
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them wi…

▾ Sunlitcompliance-trestle · compliance-trestleEPSS 0.54%via NVD
CVE-2026-45725High
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache fil…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.47%via NVD
CVE-2026-48702High· 7.5
1mo ago

Rekor is a software supply chain transparency log

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file i…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.46%via NVD
RUSTSEC-2026-0295None
1mo ago

Memory corruption bug on `ApplyResult` type

Memory corruption bug on `ApplyResult` type

▾ Sunlitz3 · z3via OSV
CVE-2026-68971Medium· 6.5
1mo ago

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. …

▾ Sunlitapache · airflowEPSS 0.59%via NVD
CVE-2026-59242Medium· 5.4
1mo ago

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user…

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user…

▾ Sunlitapache · airflowEPSS 0.80%via NVD
CVE-2026-58076High· 8.8
1mo ago

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be i…

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be i…

▾ Twilightapache · airflowEPSS 0.92%via NVD
CVE-2026-65017Medium· 6.5
1mo ago

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configurati…

▾ Sunlitapache · airflowEPSS 0.70%via NVD
CVE-2026-73294Critical· 9.9
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/projec…

▾ Midnightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.65%via NVD
CVE-2026-73262Medium· 5.4
1mo ago

Prowler is a cloud security platform

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTM…

▾ Sunlitprowler · prowlerEPSS 0.30%via NVD
CVE-2026-73295Medium· 5.4
1mo ago

Material for MkDocs is a powerful documentation framework built on top of MkDocs

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-s…

▾ Sunlitmkdocs-material · mkdocs-materialEPSS 0.33%via NVD
CVE-2026-68868Medium· 6.5
1mo ago

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal c…

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal c…

▾ Sunlitapache · apache-airflow-providers-googleEPSS 0.60%via NVD
CVE-2026-68970Medium· 6.5
1mo ago

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserial…

▾ Sunlitapache · airflowEPSS 0.39%via NVD
CVE-2026-68969Medium· 6.5
1mo ago

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`)

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking rec…

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-68968High· 7.5
1mo ago

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as …

▾ Twilightapache · airflowEPSS 0.75%via NVD
CVE-2026-68076Medium· 5.4
1mo ago

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a …

▾ Sunlitapache · airflowEPSS 0.62%via NVD
CVE-2026-67587High· 8.8
1mo ago

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default…

▾ Twilightapache · airflowEPSS 1.2%via NVD
CVE-2026-67260High· 7.3
1mo ago

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who con…

▾ Twilightapache · airflowEPSS 1.4%via NVD
CVE-2026-59244Medium· 6.5
1mo ago

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a tem…

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a tem…

▾ Sunlitapache · airflowEPSS 0.39%via NVD
CVE-2026-54183Medium· 4.3
1mo ago

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an …

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-72809High· 8.0
1mo ago

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.30%via NVD
CVE-2026-72805Medium· 5.8
1mo ago

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers or publish RoleRead…

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via NVD
CVE-2026-72789High· 8.6
1mo ago

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypte…

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.50%via NVD
CVE-2026-73429Medium· 5.3
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve255…

▾ Sunlitrussh · russhEPSS 0.51%via NVD
CVE-2026-73430Medium· 5.3
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte all-zero Q_C value. Curve25519Kex::server_dh in russh/src/kex/curve…

▾ Sunlitrussh · russhEPSS 0.60%via NVD
CVE-2026-73499High
1mo ago

etcd is a distributed key-value store for the data of a distributed system

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to recei…

▾ Twilightetcd · go.etcd.io/etcd/v3EPSS 0.66%via NVD
CVE-2026-73501Critical· 9.1
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without …

▾ MidnightRed Hat · Red Hat Edge Manager 1EPSS 0.59%via NVD
CVE-2026-73500High· 7.5
1mo ago

etcd is a distributed key-value store for the data of a distributed system

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In…

▾ TwilightRed Hat · Red Hat Trusted Artifact SignerEPSS 0.70%via NVD
CVEs tagged “osv” — page 29 · VulnSea