Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
MAL-2026-13683NoneMalicious code in kotoraka (PyPI)
Malicious code in kotoraka (PyPI)
MAL-2026-13682NoneMalicious code in btcflx (PyPI)
Malicious code in btcflx (PyPI)
MAL-2026-13681NoneMalicious code in btcflip (PyPI)
Malicious code in btcflip (PyPI)
CVE-2026-12570Medium· 5.5A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving…
MAL-2026-13667NoneMalicious code in kotanku (PyPI)
Malicious code in kotanku (PyPI)
CVE-2026-12372Low· 3.7A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, f…
RUSTSEC-2026-0242NoneSafe ErrorRegistry APIs can cause undefined behavior
Safe ErrorRegistry APIs can cause undefined behavior
RUSTSEC-2026-0240NoneEd25519 identity public keys permit universal signature forgery
Ed25519 identity public keys permit universal signature forgery
RUSTSEC-2026-0239NoneStreaming AEAD does not authenticate stream structure
Streaming AEAD does not authenticate stream structure
RUSTSEC-2026-0238NoneLow-level GCM ignores the operation nonce
Low-level GCM ignores the operation nonce
MAL-2026-13666NoneMalicious code in cubesat-upstream-driver (PyPI)
Malicious code in cubesat-upstream-driver (PyPI)
MAL-2026-13665NoneMalicious code in riakcs (PyPI)
Malicious code in riakcs (PyPI)
CVE-2026-76217Medium· 6.5GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying cred…
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers …
CVE-2026-46405Medium· 5.3OpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `log…
CVE-2026-71870Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a fo…
MAL-2026-13619NoneMalicious code in atlas-internal (PyPI)
Malicious code in atlas-internal (PyPI)
MAL-2026-13607NoneMalicious code in speed-hashes (PyPI)
Malicious code in speed-hashes (PyPI)
MAL-2026-13606NoneMalicious code in cdktn-provider-azurerm (PyPI)
Malicious code in cdktn-provider-azurerm (PyPI)
MAL-2026-13490NoneMalicious code in fast-hashes (PyPI)
Malicious code in fast-hashes (PyPI)
MAL-2026-13489NoneMalicious code in pydanticc (PyPI)
Malicious code in pydanticc (PyPI)
MAL-2026-13488NoneMalicious code in idnna (PyPI)
Malicious code in idnna (PyPI)
MAL-2026-13487NoneMalicious code in flasq (PyPI)
Malicious code in flasq (PyPI)
MAL-2026-13486NoneMalicious code in fastapii (PyPI)
Malicious code in fastapii (PyPI)
CVE-2026-71852Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font…
CVE-2026-48169High· 8.8PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key…
RUSTSEC-2026-0246None`sevenz-rust` is unmaintained
`sevenz-rust` is unmaintained
RUSTSEC-2026-0245NoneRelative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
RUSTSEC-2026-0244None`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization
`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization