VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5466 CVEsRSS

CVE-2026-61597Medium· 5.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/use…

Sunlitdjust-org · djustEPSS 0.30%via NVD
CVE-2026-61592High· 7.4
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated us…

Twilightdjust-org · djustEPSS 0.29%via NVD
CVE-2026-61594Critical· 9.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()…

Midnightdjust-org · djustEPSS 0.43%via NVD
CVE-2026-61591High· 8.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was res…

Twilightdjust-org · djustEPSS 0.17%via NVD
CVE-2026-61588Medium· 6.5
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the clie…

Sunlitdjust-org · djustEPSS 0.30%via NVD
CVE-2026-61596High· 7.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the…

Twilightdjust-org · djustEPSS 0.24%via NVD
CVE-2026-81871Medium· 6.3
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate…

Sunlitopen-telemetry · opentelemetry-goEPSS 0.20%via NVD
CVE-2026-81870Low· 2.0PoC
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively includ…

Twilightopen-telemetry · opentelemetry-goEPSS 0.19%via NVD
CVE-2026-62949Medium· 6.5
5d ago

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in a…

Sunlitronf · asyncsshEPSS 0.39%via NVD
CVE-2026-59823Medium· 5.3
5d ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_req…

SunlitBerriAI · litellmEPSS 0.44%via NVD
CVE-2026-82399High· 7.5PoC
5d ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call d…

Midnightcoredns · corednsEPSS 0.61%via NVD
CVE-2026-86003High· 7.5
5d ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.M…

Twilightcoredns · corednsEPSS 0.44%via NVD
CVE-2026-86043High· 7.5PoC
5d ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent beca…

Midnightzalando · skipperEPSS 0.50%via NVD
CVE-2026-69147Medium· 6.5PoC
5d ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards …

Twilightvllm-project · vllmEPSS 0.46%via NVD
CVE-2026-85732Medium· 4.7PoC
5d ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …

Twilightoras-project · oras-goEPSS 0.38%via NVD
CVE-2026-85731High· 8.8PoC
5d ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractT…

Midnightoras-project · oras-goEPSS 0.67%via NVD
CVE-2026-57173Medium· 6.5
5d ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_AUDIO_DECODE_DURA…

Sunlitvllm-project · vllmEPSS 0.66%via NVD
MAL-2026-16219Critical⚠ Exploited
5d ago

Malicious code in licloud (PyPI)

Malicious code in licloud (PyPI)

Abyssallicloud · licloudvia OSV
MAL-2026-16212Critical⚠ Exploited
5d ago

Malicious code in cli-anything-ai-market (PyPI)

Malicious code in cli-anything-ai-market (PyPI)

Abyssalcli-anything-ai-market · cli-anything-ai-marketvia OSV
CVE-2026-61595High· 7.7
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…

Twilightdjust · djustEPSS 0.38%via NVD
CVE-2025-59953Critical· 9.8PoC
5d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

AbyssalInternLM · lmdeployEPSS 0.68%via NVD
CVE-2026-61593High· 8.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin …

Twilightdjust · djustEPSS 0.18%via NVD
CVE-2026-82410High· 8.7
5d ago

Pocketbase is an open source web backend written in go

Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal go…

Twilightpocketbase · pocketbaseEPSS 0.58%via NVD
CVE-2026-61709Medium· 5.3
5d ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

Sunlitopenfga · openfgaEPSS 0.34%via NVD
CVE-2026-76825High· 8.4
5d ago

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…

Twilightzopefoundation · RestrictedPythonEPSS 0.57%via NVD
CVE-2026-77401Medium· 6.8
5d ago

Zope AccessControl provides a general security framework for use in Zope

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map …

Sunlitzopefoundation · AccessControlEPSS 0.37%via NVD
CVE-2026-77408Critical· 9.1
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application t…

Midnightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-77407High· 7.0
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection…

Twilightrabbitmq · amqp091-goEPSS 0.13%via NVD
CVE-2026-77406High· 8.2
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because valida…

Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-77403High· 8.9
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not en…

Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVEs tagged “osv” — page 3 · VulnSea