Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-73415High· 8.0jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObj…
CVE-2026-73498High· 7.7MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassia…
CVE-2026-9318Medium· 5.4tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated …
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated …
CVE-2026-54917HighPoCSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
CVE-2026-73087LowDozzle is a realtime log viewer for docker containers
Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 add…
CVE-2026-72925Medium· 6.1SWC is a TypeScript / JavaScript compiler written in Rust
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-contro…
CVE-2026-72920Critical· 9.8SeaweedFS is a distributed storage system
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the f…
CVE-2026-73229Medium· 4.3Django REST framework is a powerful and flexible toolkit for building Web APIs
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.…
CVE-2026-73228Medium· 5.3Django REST framework is a toolkit for building Web APIs
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser f…
RUSTSEC-2026-0270None`sp-sized-chunks` is unmaintained
`sp-sized-chunks` is unmaintained
RUSTSEC-2026-0256NonePanic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)
Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)
RUSTSEC-2026-0255NonePanic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)
RUSTSEC-2026-0254NonePanic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)
MAL-2026-13757NoneMalicious code in telebot-pro (PyPI)
Malicious code in telebot-pro (PyPI)
MAL-2026-13756NoneMalicious code in joule-sbx-poc (PyPI)
Malicious code in joule-sbx-poc (PyPI)
RUSTSEC-2026-0252NonePanic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)
Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)
MAL-2026-13732NoneMalicious code in joule-btp-extension (PyPI)
Malicious code in joule-btp-extension (PyPI)
MAL-2026-13731NoneMalicious code in morpho-sdk (PyPI)
Malicious code in morpho-sdk (PyPI)
MAL-2026-13730NoneMalicious code in euler-sdk (PyPI)
Malicious code in euler-sdk (PyPI)
MAL-2026-13729NoneMalicious code in dlmm-sdk (PyPI)
Malicious code in dlmm-sdk (PyPI)
MAL-2026-13728NoneMalicious code in dlmm (PyPI)
Malicious code in dlmm (PyPI)
CVE-2026-69112High· 7.1Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes
Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can…
CVE-2026-68871Medium· 6.5The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with thi…
CVE-2026-68872Medium· 6.5The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deploymen…
MAL-2026-13712NoneMalicious code in bigtime (PyPI)
Malicious code in bigtime (PyPI)
MAL-2026-13711NoneMalicious code in plp-contract (PyPI)
Malicious code in plp-contract (PyPI)
MAL-2026-13710NoneMalicious code in neutrl-core (PyPI)
Malicious code in neutrl-core (PyPI)
MAL-2026-13709NoneMalicious code in neutrl-contracts (PyPI)
Malicious code in neutrl-contracts (PyPI)
MAL-2026-13686NoneMalicious code in chaintest (PyPI)
Malicious code in chaintest (PyPI)
MAL-2026-13685NoneMalicious code in pytablute (PyPI)
Malicious code in pytablute (PyPI)