VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-73415High· 8.0
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObj…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.74%via NVD
CVE-2026-73498High· 7.7
1mo ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassia…

▾ Twilightmcp-atlassian · mcp-atlassianEPSS 0.48%via NVD
CVE-2026-9318Medium· 5.4
1mo ago

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated …

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated …

▾ Sunlittablib · tablibEPSS 0.30%via NVD
CVE-2026-54917HighPoC
1mo ago

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

▾ Midnightseaweedfs · github.com/seaweedfs/seaweedfsEPSS 1.6%via OSV
CVE-2026-73087Low
1mo ago

Dozzle is a realtime log viewer for docker containers

Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 add…

▾ Sunlitamir20 · github.com/amir20/dozzleEPSS 0.46%via NVD
CVE-2026-72925Medium· 6.1
1mo ago

SWC is a TypeScript / JavaScript compiler written in Rust

SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-contro…

▾ Sunlitswc · @swc/htmlEPSS 0.34%via NVD
CVE-2026-72920Critical· 9.8
1mo ago

SeaweedFS is a distributed storage system

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the f…

▾ Midnightseaweedfs · github.com/seaweedfs/seaweedfsEPSS 0.78%via NVD
CVE-2026-73229Medium· 4.3
1mo ago

Django REST framework is a powerful and flexible toolkit for building Web APIs

Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.…

▾ Sunlitdjangorestframework · djangorestframeworkEPSS 0.37%via NVD
CVE-2026-73228Medium· 5.3
1mo ago

Django REST framework is a toolkit for building Web APIs

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser f…

▾ Sunlitdjangorestframework · djangorestframeworkEPSS 0.56%via NVD
RUSTSEC-2026-0270None
1mo ago

`sp-sized-chunks` is unmaintained

`sp-sized-chunks` is unmaintained

▾ Sunlitsp-sized-chunks · sp-sized-chunksvia OSV
RUSTSEC-2026-0256None
1mo ago

Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)

Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)

▾ Sunlitcircular-buffer · circular-buffervia OSV
RUSTSEC-2026-0255None
1mo ago

Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)

Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)

▾ Sunlitsized-chunks · sized-chunksvia OSV
RUSTSEC-2026-0254None
1mo ago

Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)

Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)

▾ Sunlitsp-sized-chunks · sp-sized-chunksvia OSV
MAL-2026-13757None
1mo ago

Malicious code in telebot-pro (PyPI)

Malicious code in telebot-pro (PyPI)

▾ Sunlittelebot-pro · telebot-provia OSV
MAL-2026-13756None
1mo ago

Malicious code in joule-sbx-poc (PyPI)

Malicious code in joule-sbx-poc (PyPI)

▾ Sunlitjoule-sbx-poc · joule-sbx-pocvia OSV
RUSTSEC-2026-0252None
1mo ago

Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)

Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)

▾ Sunlitorx-split-vec · orx-split-vecvia OSV
MAL-2026-13732None
1mo ago

Malicious code in joule-btp-extension (PyPI)

Malicious code in joule-btp-extension (PyPI)

▾ Sunlitjoule-btp-extension · joule-btp-extensionvia OSV
MAL-2026-13731None
1mo ago

Malicious code in morpho-sdk (PyPI)

Malicious code in morpho-sdk (PyPI)

▾ Sunlitmorpho-sdk · morpho-sdkvia OSV
MAL-2026-13730None
1mo ago

Malicious code in euler-sdk (PyPI)

Malicious code in euler-sdk (PyPI)

▾ Sunliteuler-sdk · euler-sdkvia OSV
MAL-2026-13729None
1mo ago

Malicious code in dlmm-sdk (PyPI)

Malicious code in dlmm-sdk (PyPI)

▾ Sunlitdlmm-sdk · dlmm-sdkvia OSV
MAL-2026-13728None
1mo ago

Malicious code in dlmm (PyPI)

Malicious code in dlmm (PyPI)

▾ Sunlitdlmm · dlmmvia OSV
CVE-2026-69112High· 7.1
1mo ago

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can…

▾ Twilightaccelerate · accelerateEPSS 0.19%via NVD
CVE-2026-68871Medium· 6.5
1mo ago

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with thi…

▾ Sunlitapache · apache-airflow-providers-apache-yandexEPSS 0.60%via NVD
CVE-2026-68872Medium· 6.5
1mo ago

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deploymen…

▾ Sunlitapache · apache-airflow-providers-amazonEPSS 0.60%via NVD
MAL-2026-13712None
1mo ago

Malicious code in bigtime (PyPI)

Malicious code in bigtime (PyPI)

▾ Sunlitbigtime · bigtimevia OSV
MAL-2026-13711None
1mo ago

Malicious code in plp-contract (PyPI)

Malicious code in plp-contract (PyPI)

▾ Sunlitplp-contract · plp-contractvia OSV
MAL-2026-13710None
1mo ago

Malicious code in neutrl-core (PyPI)

Malicious code in neutrl-core (PyPI)

▾ Sunlitneutrl-core · neutrl-corevia OSV
MAL-2026-13709None
1mo ago

Malicious code in neutrl-contracts (PyPI)

Malicious code in neutrl-contracts (PyPI)

▾ Sunlitneutrl-contracts · neutrl-contractsvia OSV
MAL-2026-13686None
1mo ago

Malicious code in chaintest (PyPI)

Malicious code in chaintest (PyPI)

▾ Sunlitchaintest · chaintestvia OSV
MAL-2026-13685None
1mo ago

Malicious code in pytablute (PyPI)

Malicious code in pytablute (PyPI)

▾ Sunlitpytablute · pytablutevia OSV
CVEs tagged “osv” — page 30 · VulnSea