VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

RUSTSEC-2026-0274None
1mo ago

Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics

Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics

▾ Sunlitrtrb · rtrbvia OSV
CVE-2026-15830None
1mo ago

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as …

▾ Sunlitdjango · djangoEPSS 0.76%via OSV
MAL-2026-11521None
1mo ago

Malicious code in psbt-helpers (PyPI)

Malicious code in psbt-helpers (PyPI)

▾ Sunlitpsbt-helpers · psbt-helpersvia OSV
MAL-2026-11520None
1mo ago

Malicious code in psbt-utils (PyPI)

Malicious code in psbt-utils (PyPI)

▾ Sunlitpsbt-utils · psbt-utilsvia OSV
MAL-2026-11519None
1mo ago

Malicious code in launchdarkly-ai-server-sdk (PyPI)

Malicious code in launchdarkly-ai-server-sdk (PyPI)

▾ Sunlitlaunchdarkly-ai-server-sdk · launchdarkly-ai-server-sdkvia OSV
MAL-2026-11516None
1mo ago

Malicious code in coldcard-helpers (PyPI)

Malicious code in coldcard-helpers (PyPI)

▾ Sunlitcoldcard-helpers · coldcard-helpersvia OSV
CVE-2026-73621Medium· 5.4
1mo ago

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

▾ Sunlitgitpython · gitpythonEPSS 0.36%via OSV
CVE-2026-73619Medium· 6.5
1mo ago

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.ar…

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

▾ Sunlitgitpython · gitpythonEPSS 0.41%via OSV
RUSTSEC-2026-0243None
1mo ago

`nostr-relay-pool` is unmaintained

`nostr-relay-pool` is unmaintained

▾ Sunlitnostr-relay-pool · nostr-relay-poolvia OSV
RUSTSEC-2026-0241None
1mo ago

`nostr-keyring` is unmaintained

`nostr-keyring` is unmaintained

▾ Sunlitnostr-keyring · nostr-keyringvia OSV
RUSTSEC-2026-0237None
1mo ago

`nostr-relay-builder` is unmaintained

`nostr-relay-builder` is unmaintained

▾ Sunlitnostr-relay-builder · nostr-relay-buildervia OSV
MAL-2026-11503None
1mo ago

Malicious code in instalogin1234 (PyPI)

Malicious code in instalogin1234 (PyPI)

▾ Sunlitinstalogin1234 · instalogin1234via OSV
CVE-2026-69097High· 7.0
1mo ago

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerou…

▾ Twilightgitpython_project · gitpythonEPSS 0.27%via NVD
CVE-2026-69243High· 7.0PoC
1mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attack…

▾ MidnightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.44%via NVD
CVE-2026-69244High· 7.5
1mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker contro…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.53%via NVD
CVE-2026-69247Medium· 5.9
1mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a Recipien…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.27%via NVD
CVE-2026-69249High· 7.5
1mo ago

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed cert…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.25%via NVD
CVE-2026-69248High· 7.4
1mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate h…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.31%via NVD
CVE-2026-47211High
1mo ago

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands …

▾ Twilightouroboros-ai · ouroboros-aiEPSS 0.19%via NVD
MAL-2026-11429None
1mo ago

Malicious code in trongriden (PyPI)

Malicious code in trongriden (PyPI)

▾ Sunlittrongriden · trongridenvia OSV
MAL-2026-11428None
1mo ago

Malicious code in wacve-utils (PyPI)

Malicious code in wacve-utils (PyPI)

▾ Sunlitwacve-utils · wacve-utilsvia OSV
CVE-2026-9856High· 7.1
1mo ago

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMix…

▾ Twilighttransformers · transformersEPSS 0.46%via NVD
RUSTSEC-2026-0232High· 7.5
1mo ago

Processing of unverified relay events

Processing of unverified relay events

▾ Twilightnostr-relay-pool · nostr-relay-poolvia OSV
RUSTSEC-2026-0231High· 7.5
1mo ago

Relay authentication challenges can exhaust memory

Relay authentication challenges can exhaust memory

▾ Twilightnostr-relay-pool · nostr-relay-poolvia OSV
RUSTSEC-2026-0230High· 7.5
1mo ago

Empty NIP-50 search filters can panic

Empty NIP-50 search filters can panic

▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0229High· 7.5
1mo ago

NIP-98 authorization parsing permits resource exhaustion

NIP-98 authorization parsing permits resource exhaustion

▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0228Medium· 4.3
1mo ago

NIP-04 parsing amplifies malformed ciphertext memory use

NIP-04 parsing amplifies malformed ciphertext memory use

▾ Sunlitnostr · nostrvia OSV
RUSTSEC-2026-0227High· 7.5
1mo ago

NIP-44 v2 decryption permits resource exhaustion

NIP-44 v2 decryption permits resource exhaustion

▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0226High· 7.5
1mo ago

Wallet event parsers accept unauthenticated events

Wallet event parsers accept unauthenticated events

▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0225Medium· 5.5
1mo ago

Debug output exposes NIP-46 and NIP-60 credentials

Debug output exposes NIP-46 and NIP-60 credentials

▾ Sunlitnostr · nostrvia OSV
CVEs tagged “osv” — page 33 · VulnSea