Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
CVE-2026-64640NonePoCApache Polaris did not consistently validate storage locations supplied during table and view registration.
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration…
MAL-2026-13473NoneMalicious code in alphalend-layouts (PyPI)
Malicious code in alphalend-layouts (PyPI)
MAL-2026-13472NoneMalicious code in alphalend-abi (PyPI)
Malicious code in alphalend-abi (PyPI)
CVE-2026-67422High· 7.5pymdown-extensions is a collection of extensions for the Python Markdown library
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can parti…
CVE-2026-71554Medium· 5.3PoCh2 is a pure-Python implementation of a HTTP/2 protocol stack
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the co…
CVE-2026-18654Medium· 6.8AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
RUSTSEC-2026-0236High· 7.5A `BigInt` division panics, and two neighbouring operations answer wrongly in silence
A `BigInt` division panics, and two neighbouring operations answer wrongly in silence
MAL-2026-13426NoneMalicious code in xayoub-xctxteam (PyPI)
Malicious code in xayoub-xctxteam (PyPI)
MAL-2026-13386NoneMalicious code in decapod-common (PyPI)
Malicious code in decapod-common (PyPI)
CVE-2026-70646High· 7.5aiosend is a synchronous and asynchronous Crypto Pay API client
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to f…
CVE-2026-55524High· 7.5PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal …
CVE-2026-55522High· 7.8PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…
CVE-2026-55523HighPraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and b…
CVE-2026-71211High· 7.1PoCMLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy…
CVE-2026-34966High· 7.6Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …
MAL-2026-13380NoneMalicious code in uncrypt (PyPI)
Malicious code in uncrypt (PyPI)
MAL-2026-13373NoneMalicious code in solana-sniper-bot (PyPI)
Malicious code in solana-sniper-bot (PyPI)
MAL-2026-13372NoneMalicious code in eth-account-wallet (PyPI)
Malicious code in eth-account-wallet (PyPI)
CVE-2026-71309Highrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic…
CVE-2026-71312High· 8.0rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscap…
CVE-2026-59732Medium· 5.0rclone archive extract allows S3 destination prefix escape via crafted archive paths
rclone archive extract allows S3 destination prefix escape via crafted archive paths
CVE-2026-71313Medium· 6.9rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent …
MAL-2026-13362NoneMalicious code in mnemonic-py (PyPI)
Malicious code in mnemonic-py (PyPI)
MAL-2026-13361NoneMalicious code in defi-sdk-py (PyPI)
Malicious code in defi-sdk-py (PyPI)
MAL-2026-12503NoneMalicious code in numpyp (PyPI)
Malicious code in numpyp (PyPI)
MAL-2026-12502NoneMalicious code in gcli-control (PyPI)
Malicious code in gcli-control (PyPI)
MAL-2026-12083NoneMalicious code in crypto-wallet-sdk (PyPI)
Malicious code in crypto-wallet-sdk (PyPI)
MAL-2026-12082NoneMalicious code in crypto-trading-toolkit (PyPI)
Malicious code in crypto-trading-toolkit (PyPI)
MAL-2026-12081NoneMalicious code in bitcoinlib-py (PyPI)
Malicious code in bitcoinlib-py (PyPI)
MAL-2026-12080NoneMalicious code in bip39-py (PyPI)
Malicious code in bip39-py (PyPI)