Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
RUSTSEC-2026-0274NoneDouble free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics
Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics
CVE-2026-15830NoneAn issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as …
MAL-2026-11521NoneMalicious code in psbt-helpers (PyPI)
Malicious code in psbt-helpers (PyPI)
MAL-2026-11520NoneMalicious code in psbt-utils (PyPI)
Malicious code in psbt-utils (PyPI)
MAL-2026-11519NoneMalicious code in launchdarkly-ai-server-sdk (PyPI)
Malicious code in launchdarkly-ai-server-sdk (PyPI)
MAL-2026-11516NoneMalicious code in coldcard-helpers (PyPI)
Malicious code in coldcard-helpers (PyPI)
CVE-2026-73621Medium· 5.4GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
CVE-2026-73619Medium· 6.5GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.ar…
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
RUSTSEC-2026-0243None`nostr-relay-pool` is unmaintained
`nostr-relay-pool` is unmaintained
RUSTSEC-2026-0241None`nostr-keyring` is unmaintained
`nostr-keyring` is unmaintained
RUSTSEC-2026-0237None`nostr-relay-builder` is unmaintained
`nostr-relay-builder` is unmaintained
MAL-2026-11503NoneMalicious code in instalogin1234 (PyPI)
Malicious code in instalogin1234 (PyPI)
CVE-2026-69097High· 7.0GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerou…
CVE-2026-69243High· 7.0PoCAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attack…
CVE-2026-69244High· 7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker contro…
CVE-2026-69247Medium· 5.9cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a Recipien…
CVE-2026-69249High· 7.5python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed cert…
CVE-2026-69248High· 7.4cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate h…
CVE-2026-47211HighOuroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands …
MAL-2026-11429NoneMalicious code in trongriden (PyPI)
Malicious code in trongriden (PyPI)
MAL-2026-11428NoneMalicious code in wacve-utils (PyPI)
Malicious code in wacve-utils (PyPI)
CVE-2026-9856High· 7.1A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal
A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMix…
RUSTSEC-2026-0232High· 7.5Processing of unverified relay events
Processing of unverified relay events
RUSTSEC-2026-0231High· 7.5Relay authentication challenges can exhaust memory
Relay authentication challenges can exhaust memory
RUSTSEC-2026-0230High· 7.5Empty NIP-50 search filters can panic
Empty NIP-50 search filters can panic
RUSTSEC-2026-0229High· 7.5NIP-98 authorization parsing permits resource exhaustion
NIP-98 authorization parsing permits resource exhaustion
RUSTSEC-2026-0228Medium· 4.3NIP-04 parsing amplifies malformed ciphertext memory use
NIP-04 parsing amplifies malformed ciphertext memory use
RUSTSEC-2026-0227High· 7.5NIP-44 v2 decryption permits resource exhaustion
NIP-44 v2 decryption permits resource exhaustion
RUSTSEC-2026-0226High· 7.5Wallet event parsers accept unauthenticated events
Wallet event parsers accept unauthenticated events
RUSTSEC-2026-0225Medium· 5.5Debug output exposes NIP-46 and NIP-60 credentials
Debug output exposes NIP-46 and NIP-60 credentials